Description
In the Linux kernel, the following vulnerability has been resolved:

staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()

Two IE parsing loops are missing the header bounds checks before they
dereference pIE->length:

- issue_assocreq() walks pmlmeinfo->network.ies to build the
association request. If the stored IE data ends with only an
element_id byte and no length byte, pIE->length is read one byte
past the end of the buffer.

- join_cmd_hdl() walks pnetwork->ies during station join and has
the same problem under the same conditions.

Both buffers are filled from AP beacon and probe-response frames, so a
malicious AP that sends a truncated final IE can trigger the issue.

Apply the two-guard pattern established in update_beacon_info():
1. Break if fewer than sizeof(*pIE) bytes remain.
2. Break if the IE's declared data extends past the buffer end.
Published: 2026-07-25
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In the Linux kernel, the rtl8723bs staging driver contains two loops that parse Information Elements during association request construction and station join handling. These loops omit bounds checks before dereferencing the pIE->length field. If a malicious Access Point sends a beacon or probe‑response frame with a truncated final IE, the driver reads past the end of the buffer, causing an out‑of‑bounds read in privileged kernel space. The read can expose kernel memory contents, potentially leaking sensitive information.

Affected Systems

Systems running the Linux kernel with the rtl8723bs staging driver are affected. Kernels prior to the commits referenced in the provided Git URLs, where the rtl8723bs driver contains the vulnerable loops, are vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 8.1, indicating high severity. Its EPSS score is less than 1%, and it is not listed in the CISA KEV catalog, suggesting a low current exploitation probability. An attacker must control or manipulate a nearby wireless access point to send a malicious truncated IE; the victim device must be actively scanning or associating using the rtl8723bs hardware. Successful exploitation would result in leaking kernel memory contents, potentially leading to information disclosure.

Generated by OpenCVE AI on August 4, 2026 at 14:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the kernel patch that implements the two‑guard pattern in the rtl8723bs driver (commits shown in the Git references).
  • If a kernel upgrade is not feasible, blacklist or unload the rtl8723bs driver to prevent the hardware from processing untrusted IEs.
  • Temporarily disable the Wi‑Fi adapter or restrict the device to trusted networks until a patched kernel is deployed.

Generated by OpenCVE AI on August 4, 2026 at 14:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4717-1 linux security update
Debian DLA Debian DLA DLA-4720-1 linux security update
Debian DLA Debian DLA DLA-4723-1 linux-6.1 security update
Debian DLA Debian DLA DLA-4724-1 linux-6.12 new package
History

Sat, 01 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-20

Tue, 28 Jul 2026 00:15:00 +0000


Mon, 27 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-20

Mon, 27 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Sat, 25 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() Two IE parsing loops are missing the header bounds checks before they dereference pIE->length: - issue_assocreq() walks pmlmeinfo->network.ies to build the association request. If the stored IE data ends with only an element_id byte and no length byte, pIE->length is read one byte past the end of the buffer. - join_cmd_hdl() walks pnetwork->ies during station join and has the same problem under the same conditions. Both buffers are filled from AP beacon and probe-response frames, so a malicious AP that sends a truncated final IE can trigger the issue. Apply the two-guard pattern established in update_beacon_info(): 1. Break if fewer than sizeof(*pIE) bytes remain. 2. Break if the IE's declared data extends past the buffer end.
Title staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-05T12:42:06.371Z

Reserved: 2026-07-19T15:36:31.788Z

Link: CVE-2026-64442

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-25T10:17:28.793

Modified: 2026-08-11T15:01:50.637

Link: CVE-2026-64442

cve-icon Redhat

Severity :

Publid Date: 2026-07-25T00:00:00Z

Links: CVE-2026-64442 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T14:30:10Z

Weaknesses