Out-of-Bounds Read Vulnerability in Linux Kernel Affecting RTL8723BS Driver
CVE-2026-90016
What is CVE-2026-90016?
A vulnerability in the RTL8723BS driver of the Linux kernel allows for out-of-bounds read scenarios. The issue arises when the function rtw_restruct_wmm_ie fails to adequately check boundaries before accessing the in_ie buffer. Specifically, if a condition near the end of the buffer is not met, subsequent operations could lead to read attempts beyond allocated memory, potentially exposing sensitive information. Developers have addressed this flaw in a recent commit by introducing an explicit bounds check to prevent such occurrences, enhancing the security integrity of systems utilizing affected kernel versions.
Affected Version(s)
Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 4420cc71841b50e31a7868ef7acb011c0e08d294
Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b
Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 28a289beaf226b30b1e6e7d7b1a2946fe2d6e852