Linux Kernel Out-of-Bounds Read Vulnerability in RTL8723BS Driver

Vulnerability

A vulnerability in the Linux kernel's RTL8723BS Wi-Fi driver has been addressed. The issue involved an out-of-bounds read in the OnBeacon function, where the Extended Supported Rates (ESR) Information Element (IE) was accessed without proper boundary checks. This flaw could be exploited by a malformed beacon frame, potentially leading to a kernel panic. The vulnerability affects the Linux kernel stable tree.

Impact

Exploitation of this vulnerability could lead to an out-of-bounds read, causing a kernel panic and disrupting system operations.

Reproduction

The vulnerability can be reproduced by sending a malformed beacon frame with the ESR IE positioned at the end of the buffer. This can be done using a tool that allows for the manipulation of Wi-Fi beacon frames, such as Scapy or airodump-ng, depending on the specific environment and hardware.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version can be found in the Linux kernel documentation.

Added: Dec 16, 2025, 3:34 PM
Updated: Dec 16, 2025, 3:34 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.7
remediation
7.7
relevance
1.4
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.