SB20260824155 - Out-of-bounds read in Linux kernel rtl8723bs os_dep driver
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-74648)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information or cause a denial of service.
The vulnerability exists due to out-of-bounds read in rtw_cfg80211_monitor_if_xmit_entry() when processing truncated monitor transmit frames. A local user can send a specially crafted truncated frame to disclose sensitive information or cause a denial of service.
The issue occurs after removal of the radiotap header while handling 802.11 headers and related calculated header spans.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/6829665d050983907b560173e49dcc6c11cb2730
- https://git.kernel.org/stable/c/7b0f62d2986a28e5e4188366bc2f4e2868b14790
- https://git.kernel.org/stable/c/7edd3adb0c80d70b4237640275c559610f438476
- https://git.kernel.org/stable/c/8b3e4ed9c35d3d3b64fcc23f4a1f22b37c1865b1
- https://git.kernel.org/stable/c/a3ac6d849de5f7abe14761d741bbb843ac793454
- https://git.kernel.org/stable/c/bd88f6289b7e483216a9c1df15a0460ef9b02cb6
- https://git.kernel.org/stable/c/c5e5d78743992e235b76d2ebe5a403d60315aa8a
- https://git.kernel.org/stable/c/f03398d835f5249c49546f0eb0d0df6792b95d5f