๐Ÿ” CVE Alert

CVE-2026-64441

UNKNOWN 0.0

staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() Three IE/attribute parsing functions have missing bounds checks. rtw_get_sec_ie() and rtw_get_wapi_ie() iterate over a raw IE buffer without verifying that the header bytes (tag + length) are within the remaining buffer before reading them. Additionally, rtw_get_sec_ie() compares the 4-byte WPA OUI at cnt+2 without checking that at least 6 bytes remain, and rtw_get_wapi_ie() compares a 4-byte WAPI OUI at cnt+6 without checking that at least 10 bytes remain. rtw_get_wps_attr() reads wps_ie[0] and wps_ie+2 unconditionally at entry, before verifying that wps_ielen is large enough to contain the 6-byte WPS IE header (element_id + length + 4-byte OUI). Inside the attribute loop, get_unaligned_be16() is called on attr_ptr and attr_ptr+2 without checking that 4 bytes remain in the buffer. Add a cnt+2 bounds check before each loop body in rtw_get_sec_ie() and rtw_get_wapi_ie(), guard each multi-byte comparison with a minimum IE length requirement, add a wps_ielen < 6 early return in rtw_get_wps_attr(), and add a 4-byte bounds check in its inner loop.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
554c0a3abf216c991c5ebddcdb2c08689ecd290b < efa27d487abcdec79669a60a6d94d5d6eceb7c1d 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 2ea1ce30ead61589214240e8d33d96310fd613e5 554c0a3abf216c991c5ebddcdb2c08689ecd290b < b27ecba3196f6c14e3809595ebd69c0c2392512a 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 6ab1161e539fb7a1c8b35ff5a6ced4702e855b9c 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 4b51ee8a40fe47864197d73cc02b191de7a6b072 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 729c4e72563bda0f1725db1db9ea08df06f41d9b 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 1463ca3ec6601cbb097d8d87dbf5dcf1cb86a344
Linux / Linux
4.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/efa27d487abcdec79669a60a6d94d5d6eceb7c1d git.kernel.org: https://git.kernel.org/stable/c/2ea1ce30ead61589214240e8d33d96310fd613e5 git.kernel.org: https://git.kernel.org/stable/c/b27ecba3196f6c14e3809595ebd69c0c2392512a git.kernel.org: https://git.kernel.org/stable/c/6ab1161e539fb7a1c8b35ff5a6ced4702e855b9c git.kernel.org: https://git.kernel.org/stable/c/4b51ee8a40fe47864197d73cc02b191de7a6b072 git.kernel.org: https://git.kernel.org/stable/c/729c4e72563bda0f1725db1db9ea08df06f41d9b git.kernel.org: https://git.kernel.org/stable/c/1463ca3ec6601cbb097d8d87dbf5dcf1cb86a344