Impact
A buffer overflow occurs in the Linux kernel rtl8723bs driver when the WEP shared‑key authentication handler copies the challenge‑text element into a 128‑byte buffer without checking the attacker‑controlled length. The unchecked length allows an overlong or underlong challenge element to overwrite or underfill the buffer, leading to kernel memory corruption. Such corruption can be exploited to execute arbitrary code in kernel mode, effectively escalating privileges on the vulnerable host.
Affected Systems
The rtl8723bs wireless driver resides in the Linux kernel staging tree. Any Linux kernel installation that includes this driver—including those from common distributions—may be affected. The vulnerability is not tied to a specific kernel version, so users of any system with the vulnerable driver should consider mitigation.
Risk and Exploitability
No CVSS score or EPSS value is publicly available, and the issue is not listed in the CISA KEV catalog. Nevertheless, the flaw directly corrupts kernel memory and is reachable over the air from a malicious access point during the shared‑key authentication phase. Attackers would need a target device with the vulnerable driver and the ability to initiate a rogue authentication challenge. While exploitation likelihood is unquantified, the potential impact is severe, making the risk effectively high.
OpenCVE Enrichment