CVE-2026-64444
8.1Linux · Kernel
An out-of-bounds read vulnerability in the Linux kernel wireless driver rtl8723bs allows an adjacent attacker to cause a denial of service or information disclosure.
Executive summary
An out-of-bounds read vulnerability in the Linux kernel rtl8723bs wireless driver allows adjacent attackers to trigger memory disclosure or service disruption.
Vulnerability
This is an out-of-bounds read flaw caused by insufficient boundary checks within the OnAssocRsp information element parsing loop, triggerable by unauthenticated adjacent attackers via malicious Association Response frames.
Business impact
A successful exploit against this vulnerability can lead to kernel memory disclosure or system crashes, resulting in unexpected service downtime for affected hosts. With a CVSS score of 8.1, the high severity rating reflects the potential for severe impact on system availability and confidentiality within the local radio frequency domain.
Remediation
Immediate Action: Update the Linux kernel to version 5.15.212, 6.1.178, 6.6.145, 6.12.96, or later depending on the active branch, and reboot the system.
Proactive Monitoring: Monitor system logs for kernel panics, segmentation faults, or anomalies related to wireless driver operations and memory access violations.
Compensating Controls: Restrict wireless network access to trusted access points and utilize MAC filtering or physical security controls to limit adjacent attack vectors.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
Given the high CVSS severity and the low complexity required for exploitation on wireless interfaces, administrators must prioritize applying the latest kernel patches. Coordinate with distribution maintainers to deploy updated packages and ensure all vulnerable nodes are rebooted to clear active runtime memory.