Linux Kernel RTL8723BS Staging Driver Improper Data Validation Vulnerability

Vulnerability

A vulnerability exists in the staging driver for RTL8723BS within the Linux kernel. The issue arises from inadequate validation of data in the 'rtw_get_ie_ex()' function, which can lead to out-of-bounds read errors. This vulnerability affects several versions of the Linux kernel.

Impact

Exploitation of this vulnerability can cause out-of-bounds read errors, which may lead to memory corruption or information disclosure.

Reproduction

The vulnerability can be reproduced by using a version of the Linux kernel that includes the affected RTL8723BS staging driver. The 'rtw_get_ie_ex()' function can be called with parameters that trigger the improper data validation, allowing for an out-of-bounds read.

Remediation

Users can upgrade to the latest version of the Linux kernel, where this vulnerability has been addressed. Instructions for upgrading the kernel can be found in the official Linux kernel documentation.

Added: May 8, 2026, 9:13 PM
Updated: May 8, 2026, 9:13 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.3
remediation
7.7
relevance
7.8
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.