SB20260727128 - Out-of-bounds write in Linux kernel rtl8723bs core driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-64440)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in HT_caps_handler() when parsing a crafted 802.11 association response frame. A remote attacker can send a malicious access point response with an oversized HT Capabilities information element to cause memory corruption.
The issue can write beyond the fixed 26-byte HT_cap array into adjacent fields of struct mlme_ext_info.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/225b6d3fc7e99ac3d20b6c861d1e47d24e7ea31d
- https://git.kernel.org/stable/c/37f642d47c3648a707df3ceb092eee1adffbfd28
- https://git.kernel.org/stable/c/6f91621fc45025ad3c0be796b70e6e4cee22fc69
- https://git.kernel.org/stable/c/8c872b47c7fc32e95e0da1db7512388794adcd69
- https://git.kernel.org/stable/c/918537a0fbed85aab61fa28ad75e6279070610c9
- https://git.kernel.org/stable/c/bb3b942da4123b55d1cacf19d1a7d5ba15dbf83a
- https://git.kernel.org/stable/c/f8001e1a516ba3b495728c65b61f799cbfad6bd0