Junglewise Threat Intelligence

CVE-2026-31626: Linux Kernel use of uninitialized memory in rtl8723bs driver

CVE-2026-31626 · Severity: high · CVSS 7.1 · Published 2026-04-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel driver for Realtek RTL8723BS Wi-Fi chips, which are commonly used in tablets and low-power computers. The flaw involves the incorrect handling of security verification data, which could allow a nearby attacker to disrupt wireless connectivity or bypass certain integrity checks. This could lead to a loss of network availability or the processing of unauthorized network traffic.

Technical details

A use of uninitialized memory vulnerability (CWE-908) exists in the rtw_BIP_verify() function within the rtl8723bs staging driver (drivers/staging/rtl8723bs/core/rtw_security.c). The function fails to fully initialize an 8-byte variable (le_tmp64), only copying 6 bytes into it and leaving the remaining 2 bytes with unpredictable data from the stack. This variable is used during Broadcast Integrity Protocol (BIP) verification. An attacker within radio range (adjacent network) could potentially exploit this to cause a kernel panic (Denial of Service) or bypass integrity protections. The issue has been resolved by explicitly initializing the variable to zero.

Affected products

  • Linux Linux Kernel 4.12 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1

Timeline

  • 2026-03-21: other: Patch authored
  • 2026-04-24: disclosed: CVE published
  • 2026-06-01: patched: Patch committed to stable branches

References

Related threats