PT-2025-52898 · Rtl8187+6 · Rtl8187+6
CVE-2025-68362
·
Publicado
2025-11-21
·
Atualizado
2026-08-30
CVSS v3.1
7.0
Alta
| Vetor | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the Linux kernel’s wifi subsystem, specifically within the
rtl818x and rtl8187 drivers. The rtl8187 rx cb() function calculates the receive descriptor header address by subtracting its size from the skb tail pointer without validating if the received packet is large enough to contain this header. Receiving a truncated packet can lead to a buffer underflow, resulting in reading memory before the start of the skb data area and potentially causing a kernel panic. The issue is addressed by adding length checks for both rtl8187 and rtl8187b descriptor headers before accessing them, and dropping the packet if the check fails.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Resource Release
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Debian
Linuxmint
Linux Kernel
Ubuntu
Rtl8187
Rtl8187B
Rtl818X