{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-68190","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-30T09:28:09.373Z","datePublished":"2026-08-10T12:00:07.764Z","dateUpdated":"2026-08-19T16:31:04.402Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-19T16:31:04.402Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()\n\nrtw_get_wps_ie() iterates over IE data from network frames without\nvalidating that the IE header and payload fit within the remaining\nbuffer before reading them. Specifically:\n\n- in_ie[cnt + 1] is read without checking cnt + 1 < in_len\n- memcmp(&in_ie[cnt + 2], ...) accesses cnt + 2 without bounds check\n- in_ie[cnt + 1] is used as length without verifying payload fits\n\nAdd bounds checks at the top of the loop body to break early if fewer\nthan 2 bytes remain for the IE header, or if the declared payload\nextends past the end of the buffer. Also require at least 4 bytes of\npayload before comparing the WPS OUI."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/staging/rtl8723bs/core/rtw_ieee80211.c"],"versions":[{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"c670efe69ec8a3360bfa596436f0250a3bf15d42","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"23b630e334f7e8f76bb22a18aca350da995af905","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"b9d9a4cd2e59df7281992a076464d2536e80c674","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"630fdca3f2437fee3ffd437c4b646ccf84c7be87","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"875479f18835ac11e21a83e88f3d4dc7ccdcd0c4","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"23c31f107b4f8f420a754a45d12599bdb78f9bb8","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"0e95ff792ae0aa6fbad9455943e9e1e4062670e9","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/staging/rtl8723bs/core/rtw_ieee80211.c"],"versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.6.148"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.12.101"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.18.42"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"7.1.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/c670efe69ec8a3360bfa596436f0250a3bf15d42"},{"url":"https://git.kernel.org/stable/c/23b630e334f7e8f76bb22a18aca350da995af905"},{"url":"https://git.kernel.org/stable/c/b9d9a4cd2e59df7281992a076464d2536e80c674"},{"url":"https://git.kernel.org/stable/c/630fdca3f2437fee3ffd437c4b646ccf84c7be87"},{"url":"https://git.kernel.org/stable/c/875479f18835ac11e21a83e88f3d4dc7ccdcd0c4"},{"url":"https://git.kernel.org/stable/c/23c31f107b4f8f420a754a45d12599bdb78f9bb8"},{"url":"https://git.kernel.org/stable/c/0e95ff792ae0aa6fbad9455943e9e1e4062670e9"}],"title":"staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie()","x_generator":{"engine":"bippy-1.2.0"}}}}