Impact
An out‑of‑bounds read occurs in the rtl8723bs driver’s rtw_restruct_wmm_ie() routine. When the driver scans the WMM Information Element it can advance the pointer past the end of the buffer if the expected element is near the end of the input. The read can then expose attacker‑controlled data from the buffer. This bug does not corrupt memory but can leak sensitive information and thereby provide a foothold for further attacks in a kernel context.
Affected Systems
The flaw exists in the Linux kernel staging rtl8723bs wireless driver. Any Linux distribution that ships the kernel with this driver and has not applied the fix will be affected. Version information is not specified, so all kernels containing the unpatched rtl8723bs code are vulnerable until the patch is applied.
Risk and Exploitability
The CVSS score is 7.1, indicating a high‑severity data‑exposure vulnerability. The EPSS score is less than 1% and the issue is not listed in the CISA KEV catalog, signifying a low current exploitation probability. An attacker would need the ability to inject crafted scan or association frames via the rtl8723bs driver, making the attack local to systems that expose such frames. The lack of a public exploit and low EPSS help keep risk moderate, but the severity and potential for privilege escalation warrant prompt remediation.
OpenCVE Enrichment