Impact
In the Linux kernel's rtl8723bs staging driver, an unchecked length field in the Wi‑Fi Protected Setup (WPS) information element causes an out‑of‑bounds read and a stack buffer overflow when parsing a crafted wireless management frame. The vulnerable code copies the attribute data into a fixed stack buffer without verifying that the declared length fits within the remaining frame bytes, allowing a malicious beacon or probe response to overwrite the caller’s stack frame. This flaw can lead to corruption of kernel memory and potentially arbitrary code execution with kernel privileges, compromising the integrity and confidentiality of the entire system.
Affected Systems
This issue affects any Linux kernel that contains the Real‑tek rtl8723BS Wi‑Fi driver in the staging tree. All distributions that ship the rtl8723bs module as part of the kernel build are vulnerable until the patch that adds a full bounds check is applied. No specific kernel version is listed, so any running kernel including this driver before the commit 1463ca3ec6601 is affected.
Risk and Exploitability
The CVSS score of 8.8 marks it as high severity, and the EPSS score is below 1 %, indicating a low probability of widespread exploitation, although the potential impact is severe. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to transmit a malicious Wi‑Fi frame that contains a crafted WPS information element while the device is scanning or receiving management frames. Successful exploitation would allow a local attacker with access to the wireless interface to gain kernel privileges, potentially leading to full system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA