PT-2026-93659 · Realtek+1 · Rtl8723Bs Driver+1

CVE-2026-90018

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds read and stack buffer overflow exist in the rtw get wps attr() function within the rtl8723bs driver. The function processes WPS attributes from wireless management frames but fails to validate the attr data len variable against the remaining bytes in the Information Element (IE) before using it in a memcpy() operation. Because attr len is attacker-controlled, a crafted WPS IE in a beacon or probe response can lead to a heap out-of-bounds read or a stack overflow in the parsing thread, particularly when rtw get wps attr content() is called with specific attributes like WPS ATTR SELECTED REGISTRAR into small stack variables.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101678
CVE-2026-90018
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel
Rtl8723Bs Driver