SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64444

HIGH · CVSS 8.1 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-25 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of Association Response frames in the rtl8723bs driver, where improper bounds checking can lead to out-of-bounds reads. This flaw could be exploited by a malicious access point to cause memory corruption, potentially leading to system crashes or arbitrary code execution. Organizations using Linux systems with this driver should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-64444
Severity
HIGH
CVSS
8.1
EPSS
0.28%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop The IE parsing loop in OnAssocRsp() advances by (pIE->length + 2) each iteration but only guards on i < pkt_len. When a malicious AP sends an AssocResponse whose last IE has only one byte remaining in the frame (the element_id byte lands at pkt_len-1), the loop reads pIE->length from pframe[pkt_len], which is one byte past the allocated receive buffer. Additionally, even when the header bytes are in bounds, pIE->length itself can extend the data window beyond pkt_len, silently passing a truncated IE to the handler functions. Add two guards at the top of the loop body: 1. Break if fewer than sizeof(*pIE) bytes remain (can't read header). 2. Break if the IE's declared data extends past pkt_len.