SB2026092824 - Memory leak in Linux kernel rtl8723bs core driver



SB2026092824 - Memory leak in Linux kernel rtl8723bs core driver

Published: September 28, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026092824
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Partial DoS

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Memory leak (CVE-ID: CVE-2026-100076)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to failure to release management transmit frame and buffer resources in the rtl8723bs management frame transmission paths when handling management frame transmission error conditions. A local user can repeatedly trigger affected error paths to exhaust the management transmit pools and prevent the interface from sending beacons or probe and association responses.


Remediation

Install update from vendor's website.