PT-2026-79655 · Linux · Linux Kernel
CVE-2026-74650
·
Published
2026-08-22
·
Updated
2026-08-27
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An out-of-bounds read exists in the
WMM param handler() function within the rtl8723bs staging driver. The function copies a fixed-size WMM parameter element from a received information element without verifying if the element length is sufficient. Specifically, the handler reads 18 bytes at pIE->data + 6, requiring pIE->length to be at least 24, but it fails to validate this length. This can be triggered by a vendor-specific information element containing the WMM OUI with a length between 6 and 23 bytes. Because the OnAssocRsp() function parses frames received from an access point, this issue is reachable by a remote peer.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel