Description
In the Linux kernel, the following vulnerability has been resolved:

staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()

rtw_restruct_wmm_ie() scans in_ie for a WMM IE with:

while (i < in_len) {
...
if (i + 5 < in_len && in_ie[i] == 0xDD && ...) {
...
break;
}
i += (in_ie[i + 1] + 2); /* to the next IE element */
}

When the "i + 5 < in_len" match check fails simply because i is
within 5 bytes of the end of the buffer (i.e. no WMM IE was found
near the tail of in_ie), execution falls through to
"i += (in_ie[i + 1] + 2)", which reads in_ie[i + 1]. If i == in_len
- 1 at that point, this is a 1-byte out-of-bounds read of an
attacker-influenced IE buffer built from association/scan data.

Commit a75281626fc8f ("staging: rtl8723bs: fix potential
out-of-bounds read in rtw_restruct_wmm_ie") added the "i + 5 <
in_len" guard to the match condition itself, but did not add an
equivalent guard before the fallthrough advance, so the same class
of OOB read remained reachable through the non-matching path.

Add an explicit bounds check before advancing to the next IE.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Out‑of‑bounds read in the rtl8723bs wireless driver may expose attacker‑controlled data and could lead to information disclosure or subsequent exploitation
Action: Apply patch
AI Analysis

Impact

An out‑of‑bounds read occurs in the rtl8723bs driver’s rtw_restruct_wmm_ie() routine. When the driver scans the WMM Information Element it can advance the pointer past the end of the buffer if the expected element is near the end of the input. The read can then expose attacker‑controlled data from the buffer. This bug does not corrupt memory but can leak sensitive information and thereby provide a foothold for further attacks in a kernel context.

Affected Systems

The flaw exists in the Linux kernel staging rtl8723bs wireless driver. Any Linux distribution that ships the kernel with this driver and has not applied the fix will be affected. Version information is not specified, so all kernels containing the unpatched rtl8723bs code are vulnerable until the patch is applied.

Risk and Exploitability

The CVSS score is 7.1, indicating a high‑severity data‑exposure vulnerability. The EPSS score is less than 1% and the issue is not listed in the CISA KEV catalog, signifying a low current exploitation probability. An attacker would need the ability to inject crafted scan or association frames via the rtl8723bs driver, making the attack local to systems that expose such frames. The lack of a public exploit and low EPSS help keep risk moderate, but the severity and potential for privilege escalation warrant prompt remediation.

Generated by OpenCVE AI on September 18, 2026 at 04:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes commit a75281626fc8f, which adds a bounds check before advancing the IE pointer.
  • If the kernel cannot be updated immediately, temporarily disable or unload the rtl8723bs driver to eliminate the vulnerable code path.
  • Apply stricter input validation or restrict the handling of scan/association frames to trusted sources to reduce the chance of malformed input reaching the driver.

Generated by OpenCVE AI on September 18, 2026 at 04:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() rtw_restruct_wmm_ie() scans in_ie for a WMM IE with: while (i < in_len) { ... if (i + 5 < in_len && in_ie[i] == 0xDD && ...) { ... break; } i += (in_ie[i + 1] + 2); /* to the next IE element */ } When the "i + 5 < in_len" match check fails simply because i is within 5 bytes of the end of the buffer (i.e. no WMM IE was found near the tail of in_ie), execution falls through to "i += (in_ie[i + 1] + 2)", which reads in_ie[i + 1]. If i == in_len - 1 at that point, this is a 1-byte out-of-bounds read of an attacker-influenced IE buffer built from association/scan data. Commit a75281626fc8f ("staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie") added the "i + 5 < in_len" guard to the match condition itself, but did not add an equivalent guard before the fallthrough advance, so the same class of OOB read remained reachable through the non-matching path. Add an explicit bounds check before advancing to the next IE.
Title staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:56:59.157Z

Reserved: 2026-09-11T19:38:34.781Z

Link: CVE-2026-90016

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:14.360

Modified: 2026-10-03T11:17:45.700

Link: CVE-2026-90016

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:45:02Z

Weaknesses

No weakness.