Out-of-Bounds Read and Stack Buffer Overflow in Linux Kernel's RTL8723BS Driver
CVE-2026-90018

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90018?

The Linux kernel's RTL8723BS driver is susceptible to an out-of-bounds read and stack buffer overflow vulnerability due to improper handling of WPS attributes. The function rtw_get_wps_attr() processes WPS attributes derived from wireless management frames without adequately validating the length of attribute data obtained over the wire. This oversight allows an attacker to manipulate the attribute length, leading to an out-of-bounds read in the heap and a critical stack buffer overflow in several instances where stack variables are inadequately sized. A crafted WPS Information Element (IE) in a probe response or beacon can exploit this flaw, compromising the parsing thread's stack integrity. Proper validation checks are necessary to mitigate the risk associated with this vulnerability, ensuring the stability and security of the Linux system.

Affected Version(s)

Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 931640dfcb8cfa08f6cfb46229716d8072356420

Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 3a6457ebf39080b87c712657fdb38f34a24fc3ff

Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.