CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's iwlwifi driver, where an out-of-bounds access to the `tid_data` array occurs due to incorrect indexing by a loop counter instead of the actual TID value. Although the impact is currently limited since the multi-TID block acknowledgment feature is rarely used, it poses a potential risk for future exploitation if this feature becomes more prevalent. Linux system administrators and developers utilizing the iwlwifi driver should prioritize applying the fix to mitigate any unforeseen risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif mvmsta->tid_data was indexed by the TFD loop counter 'i' instead of the actual TID value 'tid'. This writes lq_color into a random tid_data slot unrelated to the BA entry. Since multi-TID blockack is not really in use, 'i' was always 0 and no harm was done. Add a out-of-bound check before accessing the array.