Executive brief
A security vulnerability was identified in the Linux kernel's Realtek RTL8723BS Wi-Fi driver. This flaw allows a malicious Wi-Fi access point to send specially crafted wireless frames that can crash the system or potentially allow unauthorized code execution on the connected device. Users are advised to update their Linux kernel to a patched version to mitigate this risk.
Technical details
An out-of-bounds (OOB) write vulnerability exists in the HT_caps_handler() function within the rtl8723bs staging driver (drivers/staging/rtl8723bs/core/rtw_wlan_util.c). The function fails to validate the length field of the HT Capabilities Information Element (IE) from incoming 802.11 AssocResponse frames. Because the length is a raw u8 value, an attacker-controlled access point can specify a length up to 255 bytes, overflowing the fixed 26-byte HT_cap array. This results in up to 229 bytes of OOB data being written into adjacent fields of the mlme_ext_info structure. The fix implements length truncation using umin() to ensure the iteration does not exceed the destination buffer size.
Affected products
- Linux Linux Kernel 4.12 to 6.10.10, 6.11.x, 6.12.x
Timeline
- 2026-05-22: disclosed: Vulnerability reported and patch authored
- 2026-07-25: advisory: CVE-2026-64440 published
References
- https://git.kernel.org/stable/c/225b6d3fc7e99ac3d20b6c861d1e47d24e7ea31d
- https://git.kernel.org/stable/c/37f642d47c3648a707df3ceb092eee1adffbfd28
- https://git.kernel.org/stable/c/6f91621fc45025ad3c0be796b70e6e4cee22fc69
- https://git.kernel.org/stable/c/8c872b47c7fc32e95e0da1db7512388794adcd69
- https://git.kernel.org/stable/c/918537a0fbed85aab61fa28ad75e6279070610c9
- https://git.kernel.org/stable/c/bb3b942da4123b55d1cacf19d1a7d5ba15dbf83a
- https://git.kernel.org/stable/c/f8001e1a516ba3b495728c65b61f799cbfad6bd0