๐Ÿ” CVE Alert

CVE-2026-90016

UNKNOWN 0.0

staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() rtw_restruct_wmm_ie() scans in_ie for a WMM IE with: while (i < in_len) { ... if (i + 5 < in_len && in_ie[i] == 0xDD && ...) { ... break; } i += (in_ie[i + 1] + 2); /* to the next IE element */ } When the "i + 5 < in_len" match check fails simply because i is within 5 bytes of the end of the buffer (i.e. no WMM IE was found near the tail of in_ie), execution falls through to "i += (in_ie[i + 1] + 2)", which reads in_ie[i + 1]. If i == in_len - 1 at that point, this is a 1-byte out-of-bounds read of an attacker-influenced IE buffer built from association/scan data. Commit a75281626fc8f ("staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie") added the "i + 5 < in_len" guard to the match condition itself, but did not add an equivalent guard before the fallthrough advance, so the same class of OOB read remained reachable through the non-matching path. Add an explicit bounds check before advancing to the next IE.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
554c0a3abf216c991c5ebddcdb2c08689ecd290b < 4420cc71841b50e31a7868ef7acb011c0e08d294 554c0a3abf216c991c5ebddcdb2c08689ecd290b < fd19b8895f8a91087e8a62f1e27b128025dabb95 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 28a289beaf226b30b1e6e7d7b1a2946fe2d6e852
Linux / Linux
4.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/4420cc71841b50e31a7868ef7acb011c0e08d294 git.kernel.org: https://git.kernel.org/stable/c/fd19b8895f8a91087e8a62f1e27b128025dabb95 git.kernel.org: https://git.kernel.org/stable/c/28a289beaf226b30b1e6e7d7b1a2946fe2d6e852