PT-2026-64860 · Linux+1 · Linux Kernel+1
CVE-2026-64536
·
Published
2026-07-27
·
Updated
2026-09-07
CVSS v3.1
8.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An out-of-bounds read exists in the
is ap in tkip() function within the rtl8723bs staging driver. The function iterates over Information Elements (IEs) without verifying if sufficient bytes remain in the buffer before dereferencing the IE header or its payload. Specifically, the element id and length members of the pIE pointer are accessed without ensuring the current index plus the size of the header is within the ie length boundary. Additionally, for WLAN EID VENDOR SPECIFIC and WLAN EID RSN elements, the code accesses data offsets that require minimum pIE->length values of 16 and 12 bytes, respectively, without performing these checks.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Ubuntu