CVE-2026-64441
8.8Linux · Kernel
Missing bounds checks in the Linux kernel staging rtl8723bs driver IE parsing functions lead to out-of-bounds reads.
Executive summary
An out-of-bounds read vulnerability in the Linux kernel rtl8723bs wireless staging driver allows adjacent attackers to cause potential information disclosure or denial of service.
Vulnerability
This is an out-of-bounds read vulnerability within information element parsing functions inside the rtl8723bs driver, requiring no privileges and an adjacent network attack vector.
Business impact
Successful exploitation of this flaw can lead to kernel memory disclosure or system instability, potentially resulting in localized denial of service. The high CVSS score of 8.8 reflects the severity of allowing low-privilege adjacent actors to compromise confidentiality, integrity, and availability within the kernel space.
Remediation
Immediate Action: Update the Linux kernel to version 5.15.212, 6.1.178, 6.6.145, 6.12.97, or later where the bounds checks have been properly implemented.
Proactive Monitoring: Monitor system logs for kernel panics, segmentation faults, or anomalies related to wireless driver initialization and frame processing.
Compensating Controls: Restrict physical and wireless network access to trusted personnel and segment vulnerable wireless hardware from critical network zones.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS severity and potential impact on kernel stability, administrators should prioritize applying the updated kernel packages or disabling the vulnerable staging driver module if wireless functionality is not strictly required.