Junglewise Threat Intelligence

CVE-2026-64441: Linux Kernel rtl8723bs OOB reads in IE parsing functions

CVE-2026-64441 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Realtek rtl8723bs Wi-Fi driver, which is used to manage wireless connectivity on certain devices. The issue involves improper handling of network information packets, which could allow a nearby attacker to trigger an out-of-bounds memory read. This could potentially lead to system instability or the exposure of sensitive information from the kernel's memory.

Technical details

The vulnerability exists within the staging rtl8723bs driver in the Linux kernel. Specifically, the functions rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() fail to validate the length of Information Elements (IE) and WPS attributes before performing memory reads and comparisons. In rtw_get_sec_ie() and rtw_get_wapi_ie(), the code iterates over raw IE buffers without verifying that header bytes or OUI fields are within the remaining buffer bounds. In rtw_get_wps_attr(), the code performs unconditional reads of the WPS IE header and attribute lengths without sufficient length checks. An attacker within radio range could send specially crafted Wi-Fi management frames to trigger these OOB reads. The issue has been resolved by adding explicit bounds checks before loop iterations and multi-byte comparisons.

Affected products

  • Linux Linux Kernel 554c0a3abf21 to efa27d487abcdec79669a60a6d94d5d6eceb7c1d (and other stable branches)

Timeline

  • 2026-05-22: disclosed: Initial patch submitted by Alexandru Hossu
  • 2026-07-25: advisory: CVE-2026-64441 published in NVD
  • 2026-07-07: patched: Mainline patch committed by Greg Kroah-Hartman

References

Related threats