Executive brief
A vulnerability was identified in the Linux kernel's Realtek RTL8723BS Wi-Fi driver. This driver is responsible for managing wireless network connections on certain hardware. An exploit could allow a local user to cause a system crash (denial of service), potentially disrupting operations or requiring a manual reboot.
Technical details
A NULL pointer dereference vulnerability exists in the Linux kernel within the 'staging: rtl8723bs' SDIO Wi-Fi driver. The issue occurs in the 'find_network' function in 'drivers/staging/rtl8723bs/core/rtw_mlme.c' when the variable 'pwlan' (returned by 'rtw_find_network') is not properly validated before being dereferenced or passed to 'rtw_free_network_nolock()'. A local attacker with basic privileges could trigger this condition to cause a kernel panic and denial of service. The vulnerability has been addressed by adding appropriate NULL checks in the affected code path across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 4.12 to 5.10.253, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-02-02: other: Patch authored
- 2026-05-06: disclosed: CVE published
- 2026-05-13: advisory: NVD analysis completed
References
- https://git.kernel.org/stable/c/04d24a3654ed195485bc6346a9ef326fc494a34e
- https://git.kernel.org/stable/c/1aa9c59f4b96a9056c02476c7ca89e96d15e0645
- https://git.kernel.org/stable/c/3b1d0c9a1f78836d0bce6fdd37f596f22c19b03e
- https://git.kernel.org/stable/c/41460a19654c32d39fd0e3a3671cd8d4b7b8479f
- https://git.kernel.org/stable/c/48b4dec3a8bfd667cd0cd767eaf511176193e9a1
- https://git.kernel.org/stable/c/677490a6bd4c63acdf6f48e4aaf6a23d7e6a446f
- https://git.kernel.org/stable/c/7fa16ffed2b9d9d44940990c1f31159770769aeb