Junglewise Threat Intelligence

CVE-2026-74650: Linux kernel out-of-bounds read in WMM_param_handler

CVE-2026-74650 · Severity: info · CVSS 0 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's rtl8723bs WiFi driver contains a flaw in how it processes WiFi management frames from access points. When a malformed WMM (WiFi Multimedia) information element is received during the association process, the driver reads data beyond the buffer's boundaries, potentially exposing kernel memory or causing a crash. An attacker with network proximity could exploit this by crafting a malicious association response frame.

Technical details

The vulnerability is an out-of-bounds read in the WMM_param_handler() function within drivers/staging/rtl8723bs/core/rtw_wlan_util.c. The handler copies a fixed 18-byte WMM parameter element structure (sizeof(struct WMM_para_element)) from the received information element at offset pIE->data + 6, but never validates that pIE->length is at least 24 bytes (WLAN_WMM_LEN). Two of three callers—OnAssocRsp() and join_cmd_hdl()—reach the handler after matching only the WMM OUI, allowing a short vendor-specific IE (6–23 bytes) to bypass length checks. The memcmp() and memcpy() operations then read past the element boundary. OnAssocRsp() processes frames received from an AP, making this remotely exploitable. The fix adds a length check (pIE->length != WLAN_WMM_LEN) directly in WMM_param_handler() to validate the element before access.

Affected products

  • Linux Linux kernel rtl8723bs driver (staging)

Timeline

  • 2026-08-22: disclosed: Published to NVD
  • 2026-08-19: patched: Commit ae21407350151bddfd4fea7aa39bd0643c0ca9d3 merged by Greg Kroah-Hartman

References

Related threats