๐Ÿ” CVE Alert

CVE-2026-64440

UNKNOWN 0.0

staging: rtl8723bs: fix OOB write in HT_caps_handler()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB write in HT_caps_handler() HT_caps_handler() iterates pIE->length bytes and writes into HT_caps.u.HT_cap[], which is a fixed 26-byte array (sizeof struct HT_caps_element). Because pIE->length is a raw u8 from an over-the-air 802.11 AssocResponse frame and is never validated, a malicious AP can set it up to 255, causing up to 229 bytes of out-of-bounds writes into adjacent fields of struct mlme_ext_info. Truncate the iteration count to the size of HT_caps.u.HT_cap using umin() so that data from a longer-than-expected IE is silently ignored rather than written out of bounds, preserving interoperability with APs that pad the element. An early return on oversized IEs was considered but rejected: it would bypass the pmlmeinfo->HT_caps_enable = 1 assignment that precedes the loop, silently disabling HT mode for APs that append extra bytes to the HT Capabilities IE.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
554c0a3abf216c991c5ebddcdb2c08689ecd290b < 37f642d47c3648a707df3ceb092eee1adffbfd28 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 8c872b47c7fc32e95e0da1db7512388794adcd69 554c0a3abf216c991c5ebddcdb2c08689ecd290b < bb3b942da4123b55d1cacf19d1a7d5ba15dbf83a 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 918537a0fbed85aab61fa28ad75e6279070610c9 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 6f91621fc45025ad3c0be796b70e6e4cee22fc69 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 225b6d3fc7e99ac3d20b6c861d1e47d24e7ea31d 554c0a3abf216c991c5ebddcdb2c08689ecd290b < f8001e1a516ba3b495728c65b61f799cbfad6bd0
Linux / Linux
4.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/37f642d47c3648a707df3ceb092eee1adffbfd28 git.kernel.org: https://git.kernel.org/stable/c/8c872b47c7fc32e95e0da1db7512388794adcd69 git.kernel.org: https://git.kernel.org/stable/c/bb3b942da4123b55d1cacf19d1a7d5ba15dbf83a git.kernel.org: https://git.kernel.org/stable/c/918537a0fbed85aab61fa28ad75e6279070610c9 git.kernel.org: https://git.kernel.org/stable/c/6f91621fc45025ad3c0be796b70e6e4cee22fc69 git.kernel.org: https://git.kernel.org/stable/c/225b6d3fc7e99ac3d20b6c861d1e47d24e7ea31d git.kernel.org: https://git.kernel.org/stable/c/f8001e1a516ba3b495728c65b61f799cbfad6bd0