CVE-2026-64440 Details
Description
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB write in HT_caps_handler() HT_caps_handler() iterates pIE->length bytes and writes into HT_caps.u.HT_cap[], which is a fixed 26-byte array (sizeof struct HT_caps_element). Because pIE->length is a raw u8 from an over-the-air 802.11 AssocResponse frame and is never validated, a malicious AP can set it up to 255, causing up to 229 bytes of out-of-bounds writes into adjacent fields of struct mlme_ext_info. Truncate the iteration count to the size of HT_caps.u.HT_cap using umin() so that data from a longer-than-expected IE is silently ignored rather than written out of bounds, preserving interoperability with APs that pad the element. An early return on oversized IEs was considered but rejected: it would bypass the pmlmeinfo->HT_caps_enable = 1 assignment that precedes the loop, silently disabling HT mode for APs that append extra bytes to the HT Capabilities IE.
A vulnerability has been identified in the Linux kernel's RTL8723BS Wi-Fi driver, specifically in the HT_caps_handler function. This issue arises because the function processes a length value from an unverified 802.11 Association Response frame, allowing a malicious Access Point to manipulate the length and cause out-of-bounds writes. The vulnerability can lead to overwriting adjacent fields in the mlme_ext_info structure, potentially causing memory corruption.
Users can update to the latest version of the Linux kernel where this vulnerability has been patched. The patch is available in the Linux stable tree.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/225b6d3fc7e99ac3d20b6c861d1e47d24e7ea31d | kernel.org | Patch |
| https://git.kernel.org/stable/c/37f642d47c3648a707df3ceb092eee1adffbfd28 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6f91621fc45025ad3c0be796b70e6e4cee22fc69 | kernel.org | Patch |
| https://git.kernel.org/stable/c/8c872b47c7fc32e95e0da1db7512388794adcd69 | kernel.org | Patch |
| https://git.kernel.org/stable/c/918537a0fbed85aab61fa28ad75e6279070610c9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/bb3b942da4123b55d1cacf19d1a7d5ba15dbf83a | kernel.org | Patch |
| https://git.kernel.org/stable/c/f8001e1a516ba3b495728c65b61f799cbfad6bd0 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.12, < 5.15.212 >= 5.16, < 6.1.178 >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 7.2 rc1 7.2 rc2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | Initial Analysis | [email protected] |
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 27, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |