CVE-2026-90016
Błąd odczytu poza granicami w jądrze Linuxa w rtw_restruct_wmm_ie może prowadzić do wycieku danych.
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() rtw_restruct_wmm_ie() scans in_ie for a WMM IE with: while (i < in_len) { ... if (i + 5 < in_len && in_ie[i] == 0xDD && ...) { ... break; } i += (in_ie[i + 1] + 2); /* to the next IE element */ } When the "i + 5 < in_len" match check fails simply because i is within 5 bytes of the end of the buffer (i.e. no WMM IE was found near the tail of in_ie), execution falls through to "i += (in_ie[i + 1] + 2)", which reads in_ie[i + 1]. If i == in_len - 1 at that point, this is a 1-byte out-of-bounds read of an attacker-influenced IE buffer built from association/scan data. Commit a75281626fc8f ("staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie") added the "i + 5 < in_len" guard to the match condition itself, but did not add an equivalent guard before the fallthrough advance, so the same class of OOB read remained reachable through the non-matching path. Add an explicit bounds check before advancing to the next IE.
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2026-09-16 11:17:14 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 11:17:45 UTC |
- https://git.kernel.org/stable/c/28a289beaf226b30b1e6e7d7b1a2946fe2d6e852 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/4420cc71841b50e31a7868ef7acb011c0e08d294 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/e63b72c5d7336981dfc05e5cb92becff29dfea00 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/fd19b8895f8a91087e8a62f1e27b128025dabb95 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)