8.8

CVE-2026-90018

staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr()

In the Linux kernel, the following vulnerability has been resolved:

staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr()

rtw_get_wps_attr() walks WPS attributes inside a WPS IE taken from
a wireless management frame. For each candidate attribute it only
checks that the fixed 4-byte attribute header (2-byte ID + 2-byte
length) fits inside the IE:

	if (attr_ptr + 4 > wps_ie + wps_ielen)
		break;
	u16 attr_id = get_unaligned_be16(attr_ptr);
	u16 attr_data_len = get_unaligned_be16(attr_ptr + 2);
	u16 attr_len = attr_data_len + 4;

attr_data_len (and therefore attr_len) is read directly from the
wire and is never checked against the remaining bytes in the IE
before being used as the size of:

	memcpy(buf_attr, attr_ptr, attr_len);

Since attr_len is fully attacker controlled (0 to 65535+4), this is
both a heap OOB read of wps_ie, and, more seriously, a stack buffer
overflow at several call sites where buf_attr is a single-byte
stack variable, e.g. rtw_get_wps_attr_content()'s callers passing
WPS_ATTR_SELECTED_REGISTRAR into a stack "u8 sr"/"u8
selected_registrar" (drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c,
drivers/staging/rtl8723bs/core/rtw_mlme_ext.c). A crafted WPS IE in a
beacon or probe response processed during scanning can therefore
smash the stack of the parsing thread.

rtw_get_wps_attr_content() itself has no independent length check
and simply trusts the attr_len it gets back from rtw_get_wps_attr(),
so fixing the bound here also fixes that caller.

The "attr_ptr + 4 > wps_ie + wps_ielen" header check above was added
by commit 1463ca3ec6601 ("staging: rtl8723bs: fix OOB reads in
rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()"), which
bounded the fixed header but never extended the check to cover the
variable-length attribute data that follows it. Add that missing
check before attr_len is used as a memcpy() length or accepted as a
match.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version < 931640dfcb8cfa08f6cfb46229716d8072356420
Status affected
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version < 3a6457ebf39080b87c712657fdb38f34a24fc3ff
Status affected
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version < fd5e24ea8373347d0352f153a66e8647337d1b10
Status affected
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version < a53d1ac9ce63db07943b2b2248111003851fb00f
Status affected
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version < ff61aa3289355dafa811550a1764691cd1f5d33b
Status affected
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version < 34f51d196c43a42046d229de5e79025d5ca553ca
Status affected
Version 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Version < 99aa998dec83ba180822f70e6d48a514fc81c20d
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.12
Status affected
Version 0
Version < 4.12
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.377
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/931640dfcb8cfa08f6cfb46229716d8072356420
https://git.kernel.org/stable/c/3a6457ebf39080b87c712657fdb38f34a24fc3ff
https://git.kernel.org/stable/c/fd5e24ea8373347d0352f153a66e8647337d1b10
https://git.kernel.org/stable/c/a53d1ac9ce63db07943b2b2248111003851fb00f
https://git.kernel.org/stable/c/ff61aa3289355dafa811550a1764691cd1f5d33b
https://git.kernel.org/stable/c/34f51d196c43a42046d229de5e79025d5ca553ca
https://git.kernel.org/stable/c/99aa998dec83ba180822f70e6d48a514fc81c20d