Out-of-Bounds Read Vulnerability in Linux Kernel Affecting RTL8723BS Driver
CVE-2026-90017
What is CVE-2026-90017?
A vulnerability in the Linux kernel's RTL8723BS driver has been identified, where the function rtw_action_frame_parse() does not adequately verify the length of incoming frame data before accessing it. This oversight can allow an attacker to send a maliciously crafted management action frame of a minimal length, resulting in an out-of-bounds read that could lead to unpredictable behavior or exposure of sensitive information. The issue arises from the lack of length verification on the frame_len parameter, which can potentially allow exploitation via user-influenced buffers. It's crucial to implement the necessary checks to ensure secure handling of such data.
Affected Version(s)
Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 15081ff835b29e456da29303b32efc436df04695
Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 310aaa8058d19cc431aedac0f5bb814e84479393
Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 1410bce22351ba15d8e58287cbf09d55d7f21fc9