-

CVE-2025-68254

In the Linux kernel, the following vulnerability has been resolved:

staging: rtl8723bs: fix out-of-bounds read in OnBeacon ESR IE parsing

The Extended Supported Rates (ESR) IE handling in OnBeacon accessed
*(p + 1 + ielen) and *(p + 2 + ielen) without verifying that these
offsets lie within the received frame buffer. A malformed beacon with
an ESR IE positioned at the end of the buffer could cause an
out-of-bounds read, potentially triggering a kernel panic.

Add a boundary check to ensure that the ESR IE body and the subsequent
bytes are within the limits of the frame before attempting to access
them.

This prevents OOB reads caused by malformed beacon frames.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < c03cb111628924827351e19baa5b073e9b0d723d
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Status affected
Version < bb5940193d813449540d8d3a82abc045be41f48a
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Status affected
Version < c173ce97d3f0f0c0fefa39139d6d04ba60b5db22
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Status affected
Version < d1ab7f9cee22e7b8a528da9ac953e4193b96cda5
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Status affected
Version < 38292407c2bb5b2b3131aaace4ecc7a829b40b76
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Status affected
Version < bf323db1d883c209880bd92f3b12503e3531c3fc
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Status affected
Version < 502ddcc405b69fa92e0add6c1714d654504f6fd7
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.12
Status affected
Version < 4.12
Version 0
Status unaffected
Version <= 5.15.*
Version 5.15.198
Status unaffected
Version <= 6.1.*
Version 6.1.160
Status unaffected
Version <= 6.6.*
Version 6.6.120
Status unaffected
Version <= 6.12.*
Version 6.12.62
Status unaffected
Version <= 6.17.*
Version 6.17.12
Status unaffected
Version <= 6.18.*
Version 6.18.1
Status unaffected
Version <= *
Version 6.19-rc1
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.079
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.