Impact
The rtl8723bs driver contains an out‑of‑bounds read in the rtw_action_frame_parse() function. The code indexes into the frame body without verifying that the supplied frame length is large enough. A crafted management action frame that is only the minimum 24 bytes can cause a 1‑2 byte read past the frame boundary, potentially exposing arbitrary kernel memory contents. This flaw does not allow code execution, but it can leak sensitive data such as keys or configuration information, compromising confidentiality.
Affected Systems
The vulnerability affects the staging rtl8723bs wireless driver in the Linux kernel. It impacts Linux operating systems that load this driver, regardless of distribution, because the driver resides in the kernel's staging modules. No specific kernel version range is listed in the CNA data; therefore any kernel build that includes the current rtl8723bs driver before the patch is a potential target.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact threat. The EPSS score is below 1 %, suggesting a low but not zero chance of current exploitation. The flaw is not listed in the CISA KEV catalog. Based on the exposed interface, an attacker on the same local network can transmit crafted 802.11 action frames through the device’s monitor interface, exploiting the driver’s lack of length validation. This could result in an out‑of‑bounds read that leaks kernel memory and sensitive information. Systems that enable monitor mode or frame injection are at the greatest risk.
OpenCVE Enrichment
Debian DLA
Debian DSA