Out-Of-Bounds Read Vulnerability in Linux Kernel Affecting Multiple Devices
CVE-2026-64536
What is CVE-2026-64536?
The vulnerability in the Linux kernel's rtl8723bs staging driver allows for potential out-of-bounds (OOB) reads within the is_ap_in_tkip() function. This occurs when the function iterates through Information Elements (IEs) without adequate checks to ensure sufficient bytes are available before accessing the IE header or its payload. Specifically, certain checks are missing that can lead to dereferencing invalid memory locations when IEs are truncated at the end of the buffer. The oversight can compromise system stability and lead to unintended data exposure, making it crucial for users to apply the latest patches that implement necessary bounds checks.
Affected Version(s)
Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 6f26cc55affd9d7f88ae2f5d12db4ecf9072c209