Answer in brief
CVE-2026-64445 records a High severity (CVSS 8.8) vulnerability in staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:7.2:rc1:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:7.2:rc2:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=554c0a3abf216c991c5ebddcdb2c08689ecd290b <665e1ecb68b4e8419604e70a33f02d1c8b0222c6 || >=554c0a3abf216c991c5ebddcdb2c08689ecd290b <87cccc2a767f17dcab71e3b9fe5ae29b5516c5ce || >=554c0a3abf216c991c5ebddcdb2c08689ecd290b <c9000c93078e5c0a5a651b077c0ec92a4bc7d580 || >=554c0a3abf216c991c5ebddcdb2c08689ecd290b <1f6c9d255bdda41216b6e34c96aa2b1abee0bb84 || >=554c0a3abf216c991c5ebddcdb2c08689ecd290b <3e44a7665f3abd320a80d9c64ee4a93317041b8b || >=554c0a3abf216c991c5ebddcdb2c08689ecd290b <64ec4192d9c10e96922245d4a6747304cc76b19d || >=554c0a3abf216c991c5ebddcdb2c08689ecd290b <d90b9f39f375c9826ef145605dfe97765d0ecb91 || >=554c0a3abf216c991c5ebddcdb2c08689ecd290b <a1fc19d61f661d47204f095b593de507884849f7 | 665e1ecb68b4e8419604e70a33f02d1c8b0222c6, 87cccc2a767f17dcab71e3b9fe5ae29b5516c5ce, c9000c93078e5c0a5a651b077c0ec92a4bc7d580, 1f6c9d255bdda41216b6e34c96aa2b1abee0bb84, 3e44a7665f3abd320a80d9c64ee4a93317041b8b, 64ec4192d9c10e96922245d4a6747304cc76b19d, d90b9f39f375c9826ef145605dfe97765d0ecb91, a1fc19d61f661d47204f095b593de507884849f7 |
| Linux/Linuxgeneric | 4.12 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 3, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() OnAuth() has two bugs in the shared-key authentication path. When the Privacy bit is set, rtw_wep_decrypt() is called without verifying that the frame is long enough to contain a valid WEP IV and ICV. Inside rtw_wep_decrypt(), length is computed as: length = len - WLAN_HDR_A3_LEN - iv_len and then passed as (length - 4) to crc32_le(). If len is less than WLAN_HDR_A3_LEN + iv_len + icv_len (32 bytes), length - 4 is negative and, after the implicit cast to size_t, causes crc32_le() to read far beyond the frame buffer. Add a minimum length check before accessing the IV field and calling the decryption path. When processing a seq=3 response, rtw_get_ie() stores the Challenge Text IE length in ie_len, but the subsequent memcmp() always reads 128 bytes regardless of ie_len. IEEE 802.11 mandates a challenge text of exactly 128 bytes; reject any IE whose length field differs, matching the check already applied to OnAuthClient().
Quoted source text, attributed separately from HOL analysis.