CVE-2026-64442 Details
Description
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() Two IE parsing loops are missing the header bounds checks before they dereference pIE->length: - issue_assocreq() walks pmlmeinfo->network.ies to build the association request. If the stored IE data ends with only an element_id byte and no length byte, pIE->length is read one byte past the end of the buffer. - join_cmd_hdl() walks pnetwork->ies during station join and has the same problem under the same conditions. Both buffers are filled from AP beacon and probe-response frames, so a malicious AP that sends a truncated final IE can trigger the issue. Apply the two-guard pattern established in update_beacon_info(): 1. Break if fewer than sizeof(*pIE) bytes remain. 2. Break if the IE's declared data extends past the buffer end.
A vulnerability has been identified in the Linux kernel's RTL8723BS Wi-Fi driver, specifically in the association request and station join handling functions. This issue arises from two parsing loops that fail to properly validate the length of Information Elements (IEs) before accessing them. As a result, if an Access Point (AP) sends a truncated IE, the driver may read beyond the end of the buffer, leading to out-of-bounds memory access. The vulnerability affects the Linux kernel staging area where the RTL8723BS driver is located.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been patched. Instructions for downloading the updated kernel can be found on the official Linux kernel website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/402f13ec95945f34a210b28df1f8740d3d4a58c5 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4c21eec80cf502d9ea18e0b946246b2376452786 | kernel.org | Patch |
| https://git.kernel.org/stable/c/605ebd94d0f469204f3c9f2f84acc71e43e2780f | kernel.org | Patch |
| https://git.kernel.org/stable/c/a830bdc82461353bf7b1f8a2ad2689bf5d2de444 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ad2637c46ef8b8ae0894372a2d39fdfcdc420a1e | kernel.org | Patch |
| https://git.kernel.org/stable/c/bc881c9915c4468747d0ca5fd1abd7b313cfb0f4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/c38d16b1ffac385c9e4b38447cd5c46af1114b58 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ef61d628dfad38fead1fd2e08979ae9126d011d5 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.12, < 5.10.261 >= 5.11, < 5.15.212 >= 5.16, < 6.1.178 >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 7.2 rc1 7.2 rc2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | Initial Analysis | [email protected] |
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 27, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |