SB2026091696 - Stack-based buffer overflow in Linux kernel rtl8723bs core driver
Published: September 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Stack-based buffer overflow (CVE-ID: CVE-2026-90018)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to a stack-based buffer overflow in rtw_get_wps_attr() when processing a crafted WPS information element in a wireless management frame. A remote attacker can send a crafted beacon or probe response during scanning to compromise confidentiality, integrity, and availability.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/34f51d196c43a42046d229de5e79025d5ca553ca
- https://git.kernel.org/stable/c/3a6457ebf39080b87c712657fdb38f34a24fc3ff
- https://git.kernel.org/stable/c/931640dfcb8cfa08f6cfb46229716d8072356420
- https://git.kernel.org/stable/c/99aa998dec83ba180822f70e6d48a514fc81c20d
- https://git.kernel.org/stable/c/a53d1ac9ce63db07943b2b2248111003851fb00f
- https://git.kernel.org/stable/c/fd5e24ea8373347d0352f153a66e8647337d1b10
- https://git.kernel.org/stable/c/ff61aa3289355dafa811550a1764691cd1f5d33b