7.1

CVE-2026-90016

staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()

In the Linux kernel, the following vulnerability has been resolved:

staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()

rtw_restruct_wmm_ie() scans in_ie for a WMM IE with:

	while (i < in_len) {
		...
		if (i + 5 < in_len && in_ie[i] == 0xDD && ...) {
			...
			break;
		}
		i += (in_ie[i + 1] + 2); /* to the next IE element */
	}

When the "i + 5 < in_len" match check fails simply because i is
within 5 bytes of the end of the buffer (i.e. no WMM IE was found
near the tail of in_ie), execution falls through to
"i += (in_ie[i + 1] + 2)", which reads in_ie[i + 1]. If i == in_len
- 1 at that point, this is a 1-byte out-of-bounds read of an
attacker-influenced IE buffer built from association/scan data.

Commit a75281626fc8f ("staging: rtl8723bs: fix potential
out-of-bounds read in rtw_restruct_wmm_ie") added the "i + 5 <
in_len" guard to the match condition itself, but did not add an
equivalent guard before the fallthrough advance, so the same class
of OOB read remained reachable through the non-matching path.

Add an explicit bounds check before advancing to the next IE.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version < e63b72c5d7336981dfc05e5cb92becff29dfea00
Status affected
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version < 4420cc71841b50e31a7868ef7acb011c0e08d294
Status affected
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version < fd19b8895f8a91087e8a62f1e27b128025dabb95
Status affected
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version < 28a289beaf226b30b1e6e7d7b1a2946fe2d6e852
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.12
Status affected
Version 0
Version < 4.12
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.233
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 2.8 4.2
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/4420cc71841b50e31a7868ef7acb011c0e08d294
https://git.kernel.org/stable/c/fd19b8895f8a91087e8a62f1e27b128025dabb95
https://git.kernel.org/stable/c/28a289beaf226b30b1e6e7d7b1a2946fe2d6e852
https://git.kernel.org/stable/c/e63b72c5d7336981dfc05e5cb92becff29dfea00