In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: validate individual TWT params before driver setup
ieee80211processrxtwtaction() only partially validates a received S1G TWT setup frame before queueing it.
An individual agreement can therefore reach ieee80211s1grxtwtsetup() with twt->length too short for the full struct ieee80211twtparams.
The individual path passes twt to drvaddtwtsetup(). Both the tracepoint and the driver callback consume the complete parameters block, not merely reqtype. Do not pass a short individual agreement to the driver. Broadcast agreements remain unchanged because they are rejected locally after accessing only req_type.
[edit commit message to not overclaim lack of validation nor understate driver impact]