Executive brief
A vulnerability exists in the Linux kernel driver for Realtek RTL8723BS Wi-Fi chips, which are commonly used in tablets and low-power computers. The flaw involves the incorrect handling of security verification data, which could allow a nearby attacker to disrupt wireless connectivity or bypass certain integrity checks. This could lead to a loss of network availability or the processing of unauthorized network traffic.
Technical details
A use of uninitialized memory vulnerability (CWE-908) exists in the rtw_BIP_verify() function within the rtl8723bs staging driver (drivers/staging/rtl8723bs/core/rtw_security.c). The function fails to fully initialize an 8-byte variable (le_tmp64), only copying 6 bytes into it and leaving the remaining 2 bytes with unpredictable data from the stack. This variable is used during Broadcast Integrity Protocol (BIP) verification. An attacker within radio range (adjacent network) could potentially exploit this to cause a kernel panic (Denial of Service) or bypass integrity protections. The issue has been resolved by explicitly initializing the variable to zero.
Affected products
- Linux Linux Kernel 4.12 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1
Timeline
- 2026-03-21: other: Patch authored
- 2026-04-24: disclosed: CVE published
- 2026-06-01: patched: Patch committed to stable branches
References
- https://git.kernel.org/stable/c/51532c7c1d357145f4ac561648499f7a6847f739
- https://git.kernel.org/stable/c/6792624d933146e2757b07092e93ad915cb58930
- https://git.kernel.org/stable/c/8c964b82a4e97ec7f25e17b803ee196009b38a57
- https://git.kernel.org/stable/c/9e911eead187240193516edf55a0e1ab3425aa5b
- https://git.kernel.org/stable/c/b487a7754d874230299d5a9c2710ec4df8b2ed8a
- https://git.kernel.org/stable/c/c2026c6b603ebec52f55015496703fe79077accf
- https://git.kernel.org/stable/c/c65ee4d3be5df395e48afbcd0946dd5fce4338a9