Impact
The rtl8723bs staging driver in the Linux kernel contains a faulty validation routine. After stripping a radiotap header, it reads the 802.11 frame control field without first verifying that a complete base 802.11 header remains in the socket buffer. If a frame is truncated, the driver may read beyond the end of the buffer or attempt to write an Ethernet address with insufficient data, leading to an out-of-bounds read or memory corruption.
Affected Systems
All Linux kernel builds that ship the rtl8723bs staging driver and enable monitor mode are affected. The vulnerability exists in any kernel version that does not include the patch committed in the referenced series of kernel commits; the latest mainline merge is the fix. No product‑specific version list is supplied, so all installations using the unpatched driver are at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the EPSS score of less than 1% suggests that exploitation is unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker who can transmit crafted wireless frames to a device in monitor mode could trigger the flaw, causing an out-of-bounds read or memory corruption and potentially leading to a kernel crash. The exploitation requires the device to be running a vulnerable kernel with the rtl8723bs driver loaded and monitor mode enabled; disabling monitor mode or unloading the driver can mitigate the threat.
OpenCVE Enrichment
Debian DLA
Debian DSA