{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80943","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.803Z","datePublished":"2026-09-11T19:42:15.341Z","dateUpdated":"2026-09-13T06:28:18.870Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:28:18.870Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtlwifi: rtl8192du: check QoS TID before indexing tids\n\nrtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the QoS TID\nfrom the 802.11 header and then uses it as an index into\nsta_entry->tids[]. ieee80211_get_tid() returns the low 4-bit QoS TID\nvalue, so the result can be in the range 0..15.\n\nrtlwifi only allocates MAX_TID_COUNT entries for sta_entry->tids[], and\nMAX_TID_COUNT is 9. A QoS TID greater than 8 therefore indexes past the\naggregation state array. Keep the default RTL_AGG_STOP state for\nout-of-range TIDs, matching rtl92cu_tx_fill_desc().\n\nThis issue was detected by our static analysis tool and confirmed by\nmanual audit. UBSAN validation for the same bug pattern reports an\narray-index-out-of-bounds access with index 10 for type\n'rtl_tid_data [9]'."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","baseScore":7.6,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - An adjacent Wi-Fi peer can trigger automatic open-mesh peering responses; ieee80211_get_tid() treats the self-protected action category 15 as a QoS TID, so rtl92du_tx_fill_desc() is reached over the wireless link.\nAC:L - A valid peering-open frame deterministically allocates an authorized station and transmits a category-15 action frame into the vulnerable TX descriptor path; no race or other condition outside the attacker's control is required.\nPR:N - Open 802.11s mesh accepts self-protected peering frames from unknown peers and automatically inserts an authorized station, so no credentials or local capabilities are required.\nUI:N - Once the rtl8192du interface is operating as a mesh point, mac80211 processes the attacker's frame and transmits the peering response without further victim action.\nS:U - The out-of-bounds access and any resulting crash remain in the host kernel and wireless device security authority, without crossing a VM, IOMMU, or sandbox boundary.\nC:L - The bug reads one agg_state byte at a TID-selected offset; TIDs 9-15 index past tids[9] into adjacent heap, yielding only a tightly bounded heap-state oracle rather than arbitrary disclosure.\nI:L - The access does not overwrite kernel memory or provide an arbitrary-write primitive; the fetched byte can only influence AMPDU/RTS TX descriptor fields, giving limited transmission integrity impact.\nA:H - UBSAN trap or panic-on-warning kernels can oops or panic on the deterministic bounds violation, and an adjacent peer can retrigger it after recovery."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/realtek/rtlwifi/rtl8192du/trx.c"],"versions":[{"version":"8321424134a400a5e3eb39f9acca6bc6946ff447","lessThan":"6e327f14e1c43e175bf530f9165b2cadff308553","status":"affected","versionType":"git"},{"version":"8321424134a400a5e3eb39f9acca6bc6946ff447","lessThan":"0c0b374e12d52af23ca741728db31091677cf9dc","status":"affected","versionType":"git"},{"version":"8321424134a400a5e3eb39f9acca6bc6946ff447","lessThan":"42785f7e8d31540e6172bbcf08a7cc3cae1086f8","status":"affected","versionType":"git"},{"version":"8321424134a400a5e3eb39f9acca6bc6946ff447","lessThan":"ed4f05d9f2f42fd866f55108db8123eefcc5fb33","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/realtek/rtlwifi/rtl8192du/trx.c"],"versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6e327f14e1c43e175bf530f9165b2cadff308553"},{"url":"https://git.kernel.org/stable/c/0c0b374e12d52af23ca741728db31091677cf9dc"},{"url":"https://git.kernel.org/stable/c/42785f7e8d31540e6172bbcf08a7cc3cae1086f8"},{"url":"https://git.kernel.org/stable/c/ed4f05d9f2f42fd866f55108db8123eefcc5fb33"}],"title":"wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids","x_generator":{"engine":"bippy-1.2.0"}}}}