Executive brief
A security vulnerability has been identified in the Linux kernel driver for Realtek RTL8723BS Wi-Fi chips, which are commonly used in tablets and low-power computers. An attacker within Wi-Fi range could exploit this flaw to crash the system or potentially access sensitive information from the computer's memory. This occurs during the Wi-Fi connection process when the system fails to properly check the size of incoming data packets.
Technical details
Two vulnerabilities exist in the OnAuth() function of the rtl8723bs staging driver within the Linux kernel. The first is a length underflow in rtw_wep_decrypt() where a lack of frame length verification leads to a negative value being cast to size_t, causing crc32_le() to perform an out-of-bounds read. The second is a fixed-size memcmp() that reads 128 bytes regardless of the actual Information Element (IE) length provided. These flaws are reachable via adjacent network (Wi-Fi) interaction during the shared-key authentication path. Patches have been released across multiple stable kernel branches to enforce minimum length checks and validate challenge text IE lengths.
Affected products
- Linux Linux kernel 5.10 to 6.10.1
Timeline
- 2026-05-22: disclosed: Initial patch submitted by researcher
- 2026-07-24: patched: Patch committed to stable tree
- 2026-07-25: advisory: CVE published
References
- https://git.kernel.org/stable/c/1f6c9d255bdda41216b6e34c96aa2b1abee0bb84
- https://git.kernel.org/stable/c/3e44a7665f3abd320a80d9c64ee4a93317041b8b
- https://git.kernel.org/stable/c/64ec4192d9c10e96922245d4a6747304cc76b19d
- https://git.kernel.org/stable/c/665e1ecb68b4e8419604e70a33f02d1c8b0222c6
- https://git.kernel.org/stable/c/87cccc2a767f17dcab71e3b9fe5ae29b5516c5ce
- https://git.kernel.org/stable/c/a1fc19d61f661d47204f095b593de507884849f7
- https://git.kernel.org/stable/c/c9000c93078e5c0a5a651b077c0ec92a4bc7d580