Impact
A buffer overflow occurs in the Linux kernel rtl8723bs driver when the WEP shared‑key authentication handler copies the challenge‑text element into a fixed 128‑byte buffer without validating the length provided by an attacker. The unchecked length allows an overlong or underlong challenge EID to overwrite or under‑fill the buffer, leading to kernel memory corruption. This memory corruption can be exploited to execute arbitrary code in kernel mode, effectively escalating privileges on the vulnerable host.
Affected Systems
The rtl8723bs wireless driver resides in the Linux kernel staging tree. Any Linux system that installs or includes this driver – such as common distribution kernels that ship rtl8723bs – is affected until the driver is updated with the patch that introduces the length check. No specific kernel versions are listed, so the vulnerability applies to all releases containing the unpatched driver.
Risk and Exploitability
The CVSS score of 8.8 and an EPSS score of less than 1% indicate high severity with a low probability of exploitation; the issue is not listed in the CISA KEV catalog. However, the flaw directly corrupts kernel memory and is reachable over the air from a malicious access point during the shared‑key authentication phase. Attackers would need a target device with the vulnerable driver and the ability to initiate a rogue authentication challenge. While the exploitation likelihood is low, the potential impact remains severe, making the overall risk significant.
OpenCVE Enrichment
Debian DLA
Debian DSA