PT-2026-93659 · Realtek+1 · Rtl8723Bs Driver+1
CVE-2026-90018
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An out-of-bounds read and stack buffer overflow exist in the
rtw get wps attr() function within the rtl8723bs driver. The function processes WPS attributes from wireless management frames but fails to validate the attr data len variable against the remaining bytes in the Information Element (IE) before using it in a memcpy() operation. Because attr len is attacker-controlled, a crafted WPS IE in a beacon or probe response can lead to a heap out-of-bounds read or a stack overflow in the parsing thread, particularly when rtw get wps attr content() is called with specific attributes like WPS ATTR SELECTED REGISTRAR into small stack variables.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Rtl8723Bs Driver