CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's rtlwifi driver, specifically in the rtl8192du component, where improper handling of Quality of Service (QoS) Traffic Identifier (TID) values can lead to out-of-bounds access in the tids array. This flaw allows for potential memory corruption, which could be exploited to cause system instability or unauthorized access. Organizations using affected Linux distributions with the rtl8192du driver should prioritize patching this vulnerability to mitigate risks associated with exploitation.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids rtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the QoS TID from the 802.11 header and then uses it as an index into sta_entry->tids[]. ieee80211_get_tid() returns the low 4-bit QoS TID value, so the result can be in the range 0..15. rtlwifi only allocates MAX_TID_COUNT entries for sta_entry->tids[], and MAX_TID_COUNT is 9. A QoS TID greater than 8 therefore indexes past the aggregation state array. Keep the default RTL_AGG_STOP state for out-of-range TIDs, matching rtl92cu_tx_fill_desc(). This issue was detected by our static analysis tool and confirmed by manual audit. UBSAN validation for the same bug pattern reports an array-index-out-of-bounds access with index 10 for type 'rtl_tid_data [9]'.