Back

HIGH

wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids

Published Sep 11, 2026

Description

rtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the QoS TID from the 802.11 header and then uses it as an index into sta_entry->tids[]. ieee80211_get_tid() returns the low 4-bit QoS TID value, so the result can be in the range 0..15.

rtlwifi only allocates MAX_TID_COUNT entries for sta_entry->tids[], and MAX_TID_COUNT is 9. A QoS TID greater than 8 therefore indexes past the aggregation state array. Keep the default RTL_AGG_STOP state for out-of-range TIDs, matching rtl92cu_tx_fill_desc().

This issue was detected by our static analysis tool and confirmed by manual audit. UBSAN validation for the same bug pattern reports an array-index-out-of-bounds access with index 10 for type 'rtl_tid_data [9]'.

Affected products

Remediation

No remediation recorded yet.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Sep 11, 2026
Updated Sep 13, 2026
Reserved Aug 26, 2026
NVD
Status Received
Modified Sep 13, 2026
Red Hat
Severity Moderate
Public date Sep 11, 2026
ENISA EUVD
Assigner Linux
Published Sep 11, 2026
Updated Sep 13, 2026
Exploited since n/a
EUVD-2026-76266