{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90017","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.781Z","datePublished":"2026-09-16T10:33:22.827Z","dateUpdated":"2026-09-16T14:41:35.855Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:41:35.855Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB read in rtw_action_frame_parse()\n\nrtw_action_frame_parse() takes a frame_len parameter but never\nactually checks it before indexing into the frame body:\n\n\tconst u8 *frame_body = frame + sizeof(struct ieee80211_hdr_3addr);\n\t...\n\tc = frame_body[0];\n\t...\n\ta = frame_body[1];\n\nframe_body already points 24 bytes (sizeof(struct\nieee80211_hdr_3addr)) into frame, so reading frame_body[0] and\nframe_body[1] requires frame_len >= 26. A management action frame\nshorter than that (e.g. exactly 24 bytes, the minimum a malicious\npeer can send) causes a 1-2 byte out-of-bounds read.\n\nThis is reachable from rtw_cfg80211_monitor_if_xmit_entry() and\ncfg80211_rtw_mgmt_tx() in ioctl_cfg80211.c, both of which pass\nattacker/user-influenced frame buffers and lengths straight through.\n\nAdd the missing length check before frame_body is dereferenced."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - rtw_action_frame_parse() is reached from rtw_cfg80211_rx_action() on received 802.11 public action frames (OnAction → on_action_public → on_action_public_default). A nearby attacker can inject a truncated management action frame over Wi-Fi; kernel CNA guidance maps Wi-Fi frame injection to Adjacent.\nAC:L - An adjacent attacker fully controls the action-frame length and 802.11 header. A 24- or 25-byte management action frame (header only, or header plus category) reliably hits the missing length check with no race or attacker-uncontrollable layout.\nPR:N - Public action frames are dispatched by mgt_dispatcher()/OnAction() with only a local-MAC match and no association or 802.11 authentication against the sender, so no local account or capability is required.\nUI:N - The rtl8723bs driver processes received management action frames automatically while the interface is up; no extra victim click, mount, or connect action is required at exploit time.\nS:U - The out-of-bounds read occurs in the host rtl8723bs driver and does not cross a VM, IOMMU, or other security-authority boundary.\nC:L - The flaw reads only one or two bytes past a truncated 24- or 25-byte action frame. Per kernel CNA guidance this is a strictly bounded out-of-bounds read, not an arbitrary read primitive.\nI:N - The bug is a read-only out-of-bounds access of the category/action bytes; those values are not used to write kernel memory or hijack control flow.\nA:H - A 1-2 byte kernel out-of-bounds read can oops or panic on KASAN, redzone, or hardened kernels, and an adjacent peer can repeat truncated action frames to deny availability."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/staging/rtl8723bs/core/rtw_ieee80211.c"],"versions":[{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"15081ff835b29e456da29303b32efc436df04695","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"310aaa8058d19cc431aedac0f5bb814e84479393","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"1410bce22351ba15d8e58287cbf09d55d7f21fc9","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"0b7f64c7bb9664777168768c6b44affb07dcbf24","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"136f9a3ab87ded8aaf081425cfb2059659dd9023","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"b041e3f35e0d262d42a711094ab594634d72744a","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"a54fd1a44862d263df9f8bc17fca3620be31addb","status":"affected","versionType":"git"},{"version":"554c0a3abf216c991c5ebddcdb2c08689ecd290b","lessThan":"ff917923f4fb9c83717ba135ee47d7e4c1567bb7","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/staging/rtl8723bs/core/rtw_ieee80211.c"],"versions":[{"version":"4.12","status":"affected"},{"version":"0","lessThan":"4.12","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"7.3-rc2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/15081ff835b29e456da29303b32efc436df04695"},{"url":"https://git.kernel.org/stable/c/310aaa8058d19cc431aedac0f5bb814e84479393"},{"url":"https://git.kernel.org/stable/c/1410bce22351ba15d8e58287cbf09d55d7f21fc9"},{"url":"https://git.kernel.org/stable/c/0b7f64c7bb9664777168768c6b44affb07dcbf24"},{"url":"https://git.kernel.org/stable/c/136f9a3ab87ded8aaf081425cfb2059659dd9023"},{"url":"https://git.kernel.org/stable/c/b041e3f35e0d262d42a711094ab594634d72744a"},{"url":"https://git.kernel.org/stable/c/a54fd1a44862d263df9f8bc17fca3620be31addb"},{"url":"https://git.kernel.org/stable/c/ff917923f4fb9c83717ba135ee47d7e4c1567bb7"}],"title":"staging: rtl8723bs: fix OOB read in rtw_action_frame_parse()","x_generator":{"engine":"bippy-1.2.0"}}}}