Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52736
https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2026-bulletin.html