7.6

CVE-2026-80943

wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids

In the Linux kernel, the following vulnerability has been resolved:

wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids

rtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the QoS TID
from the 802.11 header and then uses it as an index into
sta_entry->tids[]. ieee80211_get_tid() returns the low 4-bit QoS TID
value, so the result can be in the range 0..15.

rtlwifi only allocates MAX_TID_COUNT entries for sta_entry->tids[], and
MAX_TID_COUNT is 9. A QoS TID greater than 8 therefore indexes past the
aggregation state array. Keep the default RTL_AGG_STOP state for
out-of-range TIDs, matching rtl92cu_tx_fill_desc().

This issue was detected by our static analysis tool and confirmed by
manual audit. UBSAN validation for the same bug pattern reports an
array-index-out-of-bounds access with index 10 for type
'rtl_tid_data [9]'.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 8321424134a400a5e3eb39f9acca6bc6946ff447
Version < 6e327f14e1c43e175bf530f9165b2cadff308553
Status affected
Version 8321424134a400a5e3eb39f9acca6bc6946ff447
Version < 0c0b374e12d52af23ca741728db31091677cf9dc
Status affected
Version 8321424134a400a5e3eb39f9acca6bc6946ff447
Version < 42785f7e8d31540e6172bbcf08a7cc3cae1086f8
Status affected
Version 8321424134a400a5e3eb39f9acca6bc6946ff447
Version < ed4f05d9f2f42fd866f55108db8123eefcc5fb33
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.11
Status affected
Version 0
Version < 6.11
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.16
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.6 2.8 4.7
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/6e327f14e1c43e175bf530f9165b2cadff308553
https://git.kernel.org/stable/c/0c0b374e12d52af23ca741728db31091677cf9dc
https://git.kernel.org/stable/c/42785f7e8d31540e6172bbcf08a7cc3cae1086f8
https://git.kernel.org/stable/c/ed4f05d9f2f42fd866f55108db8123eefcc5fb33