Answer in brief
CVE-2026-64441 records a High severity (CVSS 8.8) vulnerability in staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:7.2:rc1:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:7.2:rc2:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=554c0a3abf216c991c5ebddcdb2c08689ecd290b <efa27d487abcdec79669a60a6d94d5d6eceb7c1d || >=554c0a3abf216c991c5ebddcdb2c08689ecd290b <2ea1ce30ead61589214240e8d33d96310fd613e5 || >=554c0a3abf216c991c5ebddcdb2c08689ecd290b <b27ecba3196f6c14e3809595ebd69c0c2392512a || >=554c0a3abf216c991c5ebddcdb2c08689ecd290b <6ab1161e539fb7a1c8b35ff5a6ced4702e855b9c || >=554c0a3abf216c991c5ebddcdb2c08689ecd290b <4b51ee8a40fe47864197d73cc02b191de7a6b072 || >=554c0a3abf216c991c5ebddcdb2c08689ecd290b <729c4e72563bda0f1725db1db9ea08df06f41d9b || >=554c0a3abf216c991c5ebddcdb2c08689ecd290b <1463ca3ec6601cbb097d8d87dbf5dcf1cb86a344 | efa27d487abcdec79669a60a6d94d5d6eceb7c1d, 2ea1ce30ead61589214240e8d33d96310fd613e5, b27ecba3196f6c14e3809595ebd69c0c2392512a, 6ab1161e539fb7a1c8b35ff5a6ced4702e855b9c, 4b51ee8a40fe47864197d73cc02b191de7a6b072, 729c4e72563bda0f1725db1db9ea08df06f41d9b, 1463ca3ec6601cbb097d8d87dbf5dcf1cb86a344 |
| Linux/Linuxgeneric | 4.12 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 3, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() Three IE/attribute parsing functions have missing bounds checks. rtw_get_sec_ie() and rtw_get_wapi_ie() iterate over a raw IE buffer without verifying that the header bytes (tag + length) are within the remaining buffer before reading them. Additionally, rtw_get_sec_ie() compares the 4-byte WPA OUI at cnt+2 without checking that at least 6 bytes remain, and rtw_get_wapi_ie() compares a 4-byte WAPI OUI at cnt+6 without checking that at least 10 bytes remain. rtw_get_wps_attr() reads wps_ie[0] and wps_ie+2 unconditionally at entry, before verifying that wps_ielen is large enough to contain the 6-byte WPS IE header (element_id + length + 4-byte OUI). Inside the attribute loop, get_unaligned_be16() is called on attr_ptr and attr_ptr+2 without checking that 4 bytes remain in the buffer. Add a cnt+2 bounds check before each loop body in rtw_get_sec_ie() and rtw_get_wapi_ie(), guard each multi-byte comparison with a minimum IE length requirement, add a wps_ielen < 6 early return in rtw_get_wps_attr(), and add a 4-byte bounds check in its inner loop.
Quoted source text, attributed separately from HOL analysis.