PT-2026-79655 · Linux · Linux Kernel

CVE-2026-74650

·

Published

2026-08-22

·

Updated

2026-08-27

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds read exists in the WMM param handler() function within the rtl8723bs staging driver. The function copies a fixed-size WMM parameter element from a received information element without verifying if the element length is sufficient. Specifically, the handler reads 18 bytes at pIE->data + 6, requiring pIE->length to be at least 24, but it fails to validate this length. This can be triggered by a vendor-specific information element containing the WMM OUI with a length between 6 and 23 bytes. Because the OnAssocRsp() function parses frames received from an access point, this issue is reachable by a remote peer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-74650

Affected Products

Linux Kernel