Out-of-Bounds Read Vulnerability in Linux Kernel Affecting RTL8723BS Driver
CVE-2026-90016

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90016?

A vulnerability in the RTL8723BS driver of the Linux kernel allows for out-of-bounds read scenarios. The issue arises when the function rtw_restruct_wmm_ie fails to adequately check boundaries before accessing the in_ie buffer. Specifically, if a condition near the end of the buffer is not met, subsequent operations could lead to read attempts beyond allocated memory, potentially exposing sensitive information. Developers have addressed this flaw in a recent commit by introducing an explicit bounds check to prevent such occurrences, enhancing the security integrity of systems utilizing affected kernel versions.

Affected Version(s)

Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 4420cc71841b50e31a7868ef7acb011c0e08d294

Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b

Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 28a289beaf226b30b1e6e7d7b1a2946fe2d6e852

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.