{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64443","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T15:36:31.788Z","datePublished":"2026-07-25T08:51:15.234Z","dateUpdated":"2026-08-17T04:55:45.615Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T04:55:45.615Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB read in update_beacon_info() IE loop\n\nThe IE parsing loop in update_beacon_info() advances by\n(pIE->length + 2) each iteration but only guards on i < len.\nWhen a malicious AP sends a Beacon whose last IE has only one byte\nremaining in the frame (the element_id byte lands at len-1), the loop\nreads pIE->length from one byte past the allocated receive buffer.\n\nAdditionally, even when the header bytes are in bounds, pIE->length\nitself can extend the data window beyond len, passing a truncated IE\nto the handler functions.\n\nAdd two guards at the top of the loop body:\n  1. Break if fewer than sizeof(*pIE) bytes remain (can't read header).\n  2. Break if the IE's declared data extends past len.\n\nAlso replace i += (pIE->length + 2) with i += sizeof(*pIE) + pIE->length\nfor consistency with the sizeof(*pIE) guards added above."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":8.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - An attacker within WiFi radio range can inject a crafted beacon spoofing the associated AP's BSSID. WiFi management-frame injection is an adjacent attack vector.\nAC:L - The malformed IE deterministically triggers the faulty parsing, and the attacker can send repeated beacons to satisfy the every-sixteenth-packet processing condition. No race or condition outside attacker control is required.\nPR:N - Ordinary beacon frames are not authenticated, even on WPA-protected networks. The driver checks association state, addresses, and BSSID, all of which an adjacent attacker can spoof without credentials or host privileges.\nUI:N - Once the interface is associated or operating in IBSS mode, crafted beacons are processed without victim action. Continuously connected embedded and mobile deployments provide this state automatically.\nS:U - The vulnerable driver and affected kernel resources belong to the same operating-system security authority. No guest-host, sandbox, or IOMMU boundary is crossed.\nC:H - Truncated WMM or HT elements can make handlers consume roughly 22 to 24 bytes beyond the logical frame from adjacent kernel skb memory. Under conservative treatment of this nontrivial kernel out-of-bounds read, confidentiality impact is High.\nI:N - The flaw performs out-of-bounds reads but provides no out-of-bounds write or control-flow primitive. Handler copies target correctly sized driver state fields.\nA:H - Out-of-bounds accesses in the kernel receive tasklet can produce an oops or panic on hardened or unfavorable memory layouts. An unauthenticated adjacent attacker can repeatedly transmit triggering beacons."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/staging/rtl8723bs/core/rtw_wlan_util.c"],"versions":[{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"5e8db4cff5b45c7c4edc8ae3f302027c3bb32b25","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"6dd5e8c3011ebabf417257d7f07901a7c4311539","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"9193c34f75fd9e1ea8a590d7cced464c3380dc29","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"bd953d52d587d42365e399b96c52dbdb13032070","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"69f174a0673b6b7a29b851adb60bc450cdc0ecc4","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"b5cc2f999927f69723ca53f1f2a3aa37dbeda907","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"ed51de4a86e173c3b0ef78e039c2e49e08b11f16","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/staging/rtl8723bs/core/rtw_wlan_util.c"],"versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.12.96"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.18.39"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"7.1.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5e8db4cff5b45c7c4edc8ae3f302027c3bb32b25"},{"url":"https://git.kernel.org/stable/c/6dd5e8c3011ebabf417257d7f07901a7c4311539"},{"url":"https://git.kernel.org/stable/c/9193c34f75fd9e1ea8a590d7cced464c3380dc29"},{"url":"https://git.kernel.org/stable/c/bd953d52d587d42365e399b96c52dbdb13032070"},{"url":"https://git.kernel.org/stable/c/69f174a0673b6b7a29b851adb60bc450cdc0ecc4"},{"url":"https://git.kernel.org/stable/c/b5cc2f999927f69723ca53f1f2a3aa37dbeda907"},{"url":"https://git.kernel.org/stable/c/ed51de4a86e173c3b0ef78e039c2e49e08b11f16"}],"title":"staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop","x_generator":{"engine":"bippy-1.2.0"}}}}