wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids
Published Sep 11, 2026
7.6
HIGHCVSS 3.1
EPSS 0.24%
Description
rtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the QoS TID from the 802.11 header and then uses it as an index into sta_entry->tids[]. ieee80211_get_tid() returns the low 4-bit QoS TID value, so the result can be in the range 0..15.
rtlwifi only allocates MAX_TID_COUNT entries for sta_entry->tids[], and MAX_TID_COUNT is 9. A QoS TID greater than 8 therefore indexes past the aggregation state array. Keep the default RTL_AGG_STOP state for out-of-range TIDs, matching rtl92cu_tx_fill_desc().
This issue was detected by our static analysis tool and confirmed by manual audit. UBSAN validation for the same bug pattern reports an array-index-out-of-bounds access with index 10 for type 'rtl_tid_data [9]'.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.11StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.11
- Version 6.12.109StatusunaffectedConstraints<=6.12.*
- Version 6.18.50StatusunaffectedConstraints<=6.18.*
- Version 7.2.4StatusunaffectedConstraints<=7.2.*
- Version 7.3-rc1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 10
kernel-rt
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 10 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-80943 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2532256 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-76266 Advisory
- https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80943.mbox
- https://git.kernel.org/stable/c/0c0b374e12d52af23ca741728db31091677cf9dc
- https://git.kernel.org/stable/c/42785f7e8d31540e6172bbcf08a7cc3cae1086f8
- https://git.kernel.org/stable/c/6e327f14e1c43e175bf530f9165b2cadff308553
- https://git.kernel.org/stable/c/ed4f05d9f2f42fd866f55108db8123eefcc5fb33
- https://nvd.nist.gov/vuln/detail/CVE-2026-80943
- https://www.cve.org/CVERecord?id=CVE-2026-80943
Change history (0)
No recorded changes yet.