-
CVE-2026-64446
- EPSS 0.2%
- Veröffentlicht 25.07.2026 08:51:17
- Zuletzt bearbeitet 17.08.2026 05:17:49
- CVE-Watchlists
- Unerledigt
staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()
supplicant_ie is a 256-byte array in struct security_priv. The WPA and
WPA2 IE copy paths use:
memcpy(padapter->securitypriv.supplicant_ie, &pwpa[0], wpa_ielen + 2);
where wpa_ielen is the raw IE length field (u8, 0-255). When a local user
supplies a connect request via nl80211 with a crafted WPA IE of length 255,
wpa_ielen + 2 equals 257, overflowing the 256-byte buffer by one byte into
the adjacent last_mic_err_time field.
rtw_parse_wpa_ie() does not prevent this: its length consistency check
compares *(wpa_ie+1) against (u8)(wpa_ie_len-2), which is (u8)(255) == 255
when wpa_ie_len = 257, so the check passes silently.
Add explicit bounds checks for both the WPA and WPA2 paths before the
memcpy, rejecting any IE whose total size (wpa_ielen + 2) exceeds the
supplicant_ie buffer.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version <
a94a643a80a84ceb8139061c3d6bf988d75e45a5
Status
affected
Version
554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version <
2131621986c62c86109ce4d84cf73a73757eb8a6
Status
affected
Version
554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version <
6f20d7b0ee47c470734a69379b0fc6647c519603
Status
affected
Version
554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version <
5d7812360abf3143afcbf5efe4ef242448fa1f28
Status
affected
Version
554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version <
46f66c16a95191d9aca07a72ae6b1252a244e26c
Status
affected
Version
554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version <
b9c4bf133c3c47e23baf4f5403b98a953bf58606
Status
affected
Version
554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version <
138cd190efd56ab36c9fdd8fef8749d06937f24b
Status
affected
Version
554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version <
5a752a616e756844388a1a45404db9fc29fec655
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
4.12
Status
affected
Version
0
Version <
4.12
Status
unaffected
Version <=
5.10.*
Version
5.10.261
Status
unaffected
Version <=
5.15.*
Version
5.15.212
Status
unaffected
Version <=
6.1.*
Version
6.1.178
Status
unaffected
Version <=
6.6.*
Version
6.6.145
Status
unaffected
Version <=
6.12.*
Version
6.12.96
Status
unaffected
Version <=
6.18.*
Version
6.18.39
Status
unaffected
Version <=
7.1.*
Version
7.1.4
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.095 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/a94a643a80a84ceb8139061c3d6bf988d75e45a5
https://git.kernel.org/stable/c/2131621986c62c86109ce4d84cf73a73757eb8a6
https://git.kernel.org/stable/c/6f20d7b0ee47c470734a69379b0fc6647c519603
https://git.kernel.org/stable/c/5d7812360abf3143afcbf5efe4ef242448fa1f28
https://git.kernel.org/stable/c/46f66c16a95191d9aca07a72ae6b1252a244e26c
https://git.kernel.org/stable/c/b9c4bf133c3c47e23baf4f5403b98a953bf58606
https://git.kernel.org/stable/c/138cd190efd56ab36c9fdd8fef8749d06937f24b
https://git.kernel.org/stable/c/5a752a616e756844388a1a45404db9fc29fec655