CVE-2026-64441

8.8

Linux · Kernel

Missing bounds checks in the Linux kernel staging rtl8723bs driver IE parsing functions lead to out-of-bounds reads.

Executive summary

An out-of-bounds read vulnerability in the Linux kernel rtl8723bs wireless staging driver allows adjacent attackers to cause potential information disclosure or denial of service.

Vulnerability

This is an out-of-bounds read vulnerability within information element parsing functions inside the rtl8723bs driver, requiring no privileges and an adjacent network attack vector.

Business impact

Successful exploitation of this flaw can lead to kernel memory disclosure or system instability, potentially resulting in localized denial of service. The high CVSS score of 8.8 reflects the severity of allowing low-privilege adjacent actors to compromise confidentiality, integrity, and availability within the kernel space.

Remediation

Immediate Action: Update the Linux kernel to version 5.15.212, 6.1.178, 6.6.145, 6.12.97, or later where the bounds checks have been properly implemented.

Proactive Monitoring: Monitor system logs for kernel panics, segmentation faults, or anomalies related to wireless driver initialization and frame processing.

Compensating Controls: Restrict physical and wireless network access to trusted personnel and segment vulnerable wireless hardware from critical network zones.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS severity and potential impact on kernel stability, administrators should prioritize applying the updated kernel packages or disabling the vulnerable staging driver module if wireless functionality is not strictly required.

More Linux CVEs

Sources