CVE-2026-64442
8.1Linux · Kernel
An out-of-bounds read vulnerability in the Linux kernel staging rtl8723bs driver allows a malicious access point to cause information disclosure or denial of service via crafted IE loops.
Executive summary
An out-of-bounds read vulnerability in the Linux kernel rtl8723bs wireless staging driver allows adjacent attackers to cause information disclosure or denial of service.
Vulnerability
This is an out-of-bounds read flaw caused by missing header bounds checks in information element parsing loops within the issue_assocreq and join_cmd_hdl functions, requiring no privileges and no user interaction from an adjacent network position.
Business impact
A successful exploit can lead to unauthorized disclosure of sensitive kernel memory or trigger a system crash resulting in denial of service for wireless clients. With a CVSS score of 8.1, the vulnerability presents a high severity risk due to the potential for operational disruption and memory leakage within the networking subsystem of affected hosts.
Remediation
Immediate Action: Update the Linux kernel to version 5.10.261, 5.15.212, 6.1.178, 6.6.145, or the latest stable release incorporating the upstream fix commits.
Proactive Monitoring: Monitor system logs for kernel panics, segmentation faults, or unexpected reboots associated with wireless interface driver operations.
Compensating Controls: Restrict wireless network associations to trusted access points and utilize network segmentation to limit exposure to potentially malicious broadcast frames.
Exploitation status
Public Exploit Available: No
Analyst recommendation
System administrators maintaining wireless infrastructure running the affected rtl8723bs staging driver must apply the official kernel patches immediately. Promptly updating the kernel prevents potential information leaks and denial of service attacks originating from malicious or spoofed wireless access points.