PT-2026-57566 · Nordic Semiconductor · Nrf70 Wi-Fi Driver
CVE-2026-10664
·
Published
2026-07-12
·
Updated
2026-07-12
CVSS v3.1
5.0
Medium
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
nRF70 Wi-Fi driver versions prior to v4.4.1
Description
The power-save event handler
nrf wifi event proc get power save info() in drivers/wifi/nrf wifi/src/wifi mgmt.c fails to validate the num twt flows value or the event len when copying Target Wake Time (TWT) flow entries into the fixed-size twt flows array of a wifi ps config struct. If num twt flows exceeds the maximum limit of 8, an out-of-bounds write occurs, typically affecting the caller's stack. This issue requires the nRF70 co-processor firmware to emit a malformed event in response to a host-initiated power-save GET request.Recommendations
Update the nRF70 Wi-Fi driver to version v4.4.1 or later.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nrf70 Wi-Fi Driver