Out-of-bounds read in Linux kernel - CVE-2026-64443
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the update_beacon_info() IE parsing loop in rtl8723bs when parsing a crafted Beacon frame from a malicious access point. A remote attacker can send a specially crafted Beacon frame to disclose sensitive information.
The issue can be triggered when the last information element is truncated or when an information element declares a length that extends past the available frame data.
Affected software
How to mitigate CVE-2026-64443
External References
- https://git.kernel.org/stable/c/5e8db4cff5b45c7c4edc8ae3f302027c3bb32b25
- https://git.kernel.org/stable/c/69f174a0673b6b7a29b851adb60bc450cdc0ecc4
- https://git.kernel.org/stable/c/6dd5e8c3011ebabf417257d7f07901a7c4311539
- https://git.kernel.org/stable/c/9193c34f75fd9e1ea8a590d7cced464c3380dc29
- https://git.kernel.org/stable/c/b5cc2f999927f69723ca53f1f2a3aa37dbeda907
- https://git.kernel.org/stable/c/bd953d52d587d42365e399b96c52dbdb13032070
- https://git.kernel.org/stable/c/ed51de4a86e173c3b0ef78e039c2e49e08b11f16