๐Ÿ” CVE Alert

CVE-2026-90017

UNKNOWN 0.0

staging: rtl8723bs: fix OOB read in rtw_action_frame_parse()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() rtw_action_frame_parse() takes a frame_len parameter but never actually checks it before indexing into the frame body: const u8 *frame_body = frame + sizeof(struct ieee80211_hdr_3addr); ... c = frame_body[0]; ... a = frame_body[1]; frame_body already points 24 bytes (sizeof(struct ieee80211_hdr_3addr)) into frame, so reading frame_body[0] and frame_body[1] requires frame_len >= 26. A management action frame shorter than that (e.g. exactly 24 bytes, the minimum a malicious peer can send) causes a 1-2 byte out-of-bounds read. This is reachable from rtw_cfg80211_monitor_if_xmit_entry() and cfg80211_rtw_mgmt_tx() in ioctl_cfg80211.c, both of which pass attacker/user-influenced frame buffers and lengths straight through. Add the missing length check before frame_body is dereferenced.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
554c0a3abf216c991c5ebddcdb2c08689ecd290b < 15081ff835b29e456da29303b32efc436df04695 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 310aaa8058d19cc431aedac0f5bb814e84479393 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 1410bce22351ba15d8e58287cbf09d55d7f21fc9 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 0b7f64c7bb9664777168768c6b44affb07dcbf24 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 136f9a3ab87ded8aaf081425cfb2059659dd9023 554c0a3abf216c991c5ebddcdb2c08689ecd290b < b041e3f35e0d262d42a711094ab594634d72744a 554c0a3abf216c991c5ebddcdb2c08689ecd290b < a54fd1a44862d263df9f8bc17fca3620be31addb 554c0a3abf216c991c5ebddcdb2c08689ecd290b < ff917923f4fb9c83717ba135ee47d7e4c1567bb7
Linux / Linux
4.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/15081ff835b29e456da29303b32efc436df04695 git.kernel.org: https://git.kernel.org/stable/c/310aaa8058d19cc431aedac0f5bb814e84479393 git.kernel.org: https://git.kernel.org/stable/c/1410bce22351ba15d8e58287cbf09d55d7f21fc9 git.kernel.org: https://git.kernel.org/stable/c/0b7f64c7bb9664777168768c6b44affb07dcbf24 git.kernel.org: https://git.kernel.org/stable/c/136f9a3ab87ded8aaf081425cfb2059659dd9023 git.kernel.org: https://git.kernel.org/stable/c/b041e3f35e0d262d42a711094ab594634d72744a git.kernel.org: https://git.kernel.org/stable/c/a54fd1a44862d263df9f8bc17fca3620be31addb git.kernel.org: https://git.kernel.org/stable/c/ff917923f4fb9c83717ba135ee47d7e4c1567bb7