CVE-2026-43386

ANALYSIS PENDING

staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie The current code checks 'i + 5 < in_len' at the end of the if statement. However, it accesses 'in_ie[i + 5]' before that check, which can lead to an out-of-bounds read. Move the length check to the beginning of the conditional to ensure the index is within bounds before accessing the array.

Scores

EPSS 0.0003
EPSS Percentile 9.6%

Details

Status published
Products (18)
Linux/Linux < 4.12
Linux/Linux 4.12
Linux/Linux 5.10.253 - 5.10.*
Linux/Linux 5.15.203 - 5.15.*
Linux/Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b - 12cc6e8f8d4245b7b5a408c6fc8ab1d098d67020
Linux/Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b - 209644e25757c499e1c1f08c071ea0386d4448b6
Linux/Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b - 4dd2d9cf563c54e09d5f7eacf95c5b8f538b513b
Linux/Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b - 6ff2243d5e05a5239e39d4ba61d96b0ea3bf7259
Linux/Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b - 768f25613a9fe6766d15a4a72979657adfc1c6d8
Linux/Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b - a75281626fc8fa6dc6c9cc314ee423e8bc45203b
... and 8 more
Published May 08, 2026
Tracked Since May 08, 2026