CVE-2026-64443 Details
Description
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop The IE parsing loop in update_beacon_info() advances by (pIE->length + 2) each iteration but only guards on i < len. When a malicious AP sends a Beacon whose last IE has only one byte remaining in the frame (the element_id byte lands at len-1), the loop reads pIE->length from one byte past the allocated receive buffer. Additionally, even when the header bytes are in bounds, pIE->length itself can extend the data window beyond len, passing a truncated IE to the handler functions. Add two guards at the top of the loop body: 1. Break if fewer than sizeof(*pIE) bytes remain (can't read header). 2. Break if the IE's declared data extends past len. Also replace i += (pIE->length + 2) with i += sizeof(*pIE) + pIE->length for consistency with the sizeof(*pIE) guards added above.
A vulnerability allowing an out-of-bounds read has been identified in the Linux kernel's RTL8723BS Wi-Fi driver, specifically within the 'update_beacon_info' function. This issue arises because the Information Element (IE) parsing loop advances by the length of the IE plus two bytes for each iteration, but only checks that the index is less than the total length of the packet. As a result, when a malicious Access Point (AP) sends a Beacon frame with a last IE that leaves only one byte remaining (with the element ID byte positioned at the last index), the loop can read the IE length from beyond the allocated buffer. Furthermore, even if the header bytes are within bounds, the declared length can still truncate the IE, passing incomplete data to the handler functions. The vulnerability has been addressed by adding two safeguards at the beginning of the loop: one to ensure that enough bytes remain to read the header, and another to verify that the IE's declared data does not exceed the length of the packet. Additionally, the loop increment has been modified for consistency with the new safeguards.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version are available on the official Linux kernel website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/5e8db4cff5b45c7c4edc8ae3f302027c3bb32b25 | kernel.org | Patch |
| https://git.kernel.org/stable/c/69f174a0673b6b7a29b851adb60bc450cdc0ecc4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6dd5e8c3011ebabf417257d7f07901a7c4311539 | kernel.org | Patch |
| https://git.kernel.org/stable/c/9193c34f75fd9e1ea8a590d7cced464c3380dc29 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b5cc2f999927f69723ca53f1f2a3aa37dbeda907 | kernel.org | Patch |
| https://git.kernel.org/stable/c/bd953d52d587d42365e399b96c52dbdb13032070 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ed51de4a86e173c3b0ef78e039c2e49e08b11f16 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.12, < 5.15.212 >= 5.16, < 6.1.178 >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 7.2 rc1 7.2 rc2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | Initial Analysis | [email protected] |
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 27, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |