Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64443

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
25/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop<br /> <br /> The IE parsing loop in update_beacon_info() advances by<br /> (pIE-&gt;length + 2) each iteration but only guards on i length from one byte past the allocated receive buffer.<br /> <br /> Additionally, even when the header bytes are in bounds, pIE-&gt;length<br /> itself can extend the data window beyond len, passing a truncated IE<br /> to the handler functions.<br /> <br /> Add two guards at the top of the loop body:<br /> 1. Break if fewer than sizeof(*pIE) bytes remain (can&amp;#39;t read header).<br /> 2. Break if the IE&amp;#39;s declared data extends past len.<br /> <br /> Also replace i += (pIE-&gt;length + 2) with i += sizeof(*pIE) + pIE-&gt;length<br /> for consistency with the sizeof(*pIE) guards added above.

Impacto