PT-2026-57566 · Nordic Semiconductor · Nrf70 Wi-Fi Driver

CVE-2026-10664

·

Published

2026-07-12

·

Updated

2026-07-12

CVSS v3.1

5.0

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions nRF70 Wi-Fi driver versions prior to v4.4.1
Description The power-save event handler nrf wifi event proc get power save info() in drivers/wifi/nrf wifi/src/wifi mgmt.c fails to validate the num twt flows value or the event len when copying Target Wake Time (TWT) flow entries into the fixed-size twt flows array of a wifi ps config struct. If num twt flows exceeds the maximum limit of 8, an out-of-bounds write occurs, typically affecting the caller's stack. This issue requires the nRF70 co-processor firmware to emit a malformed event in response to a host-initiated power-save GET request.
Recommendations Update the nRF70 Wi-Fi driver to version v4.4.1 or later.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10664
GHSA-3R6J-PM38-R43M

Affected Products

Nrf70 Wi-Fi Driver