PT-2026-64667 · Linux+1 · Linux Kernel+1

CVE-2026-64446

·

Published

2026-07-25

·

Updated

2026-09-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A heap buffer overflow exists in the rtw cfg80211 set wpa ie() function within the rtl8723bs staging driver. The issue occurs because the supplicant ie array in struct security priv is 256 bytes, but the copy process uses a length of wpa ielen + 2. If a local user provides a crafted WPA Information Element (IE) with a length of 255 via nl80211, the resulting length of 257 overflows the buffer by one byte, affecting the adjacent last mic err time field. The rtw parse wpa ie() function fails to prevent this due to an insufficient length consistency check.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64446
ECHO-9CE2-204A-F379
OPENSUSE-SU-2026:11476-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu