PT-2025-51668 · Realtek+4 · Rtl8723Bs+4

Published

2025-11-27

·

Updated

2026-05-11

·

CVE-2025-68255

CVSS v2.0

7.7

High

VectorAV:A/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to the rtl8723bs driver. Specifically, a stack buffer overflow can occur during the parsing of Supported Rates Information Element (IE) within Association Request frames. A malicious station can exploit this by advertising an IE length exceeding 16 bytes, leading to a stack buffer overflow when copying data into a fixed-size 16-byte stack buffer. This issue can be triggered by malformed association requests, potentially causing kernel stack corruption. The vulnerability is addressed by clamping the IE length to the buffer size before copying and correcting bounds checks during the merging of Extended Supported Rates.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-01489
CVE-2025-68255
ECHO-2DC7-2951-40FE
OPENSUSE-SU-2025:15836-1
OPENSUSE-SU-2026:10301-1
OPENSUSE-SU-2026:20145-1
SUSE-SU-2026:0278-1
SUSE-SU-2026:0281-1
SUSE-SU-2026:0315-1
SUSE-SU-2026:20207-1
SUSE-SU-2026:20220-1
SUSE-SU-2026:20228-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8094-1
USN-8094-2
USN-8094-3
USN-8094-4
USN-8094-5
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8116-1
USN-8141-1
USN-8152-1
USN-8163-1
USN-8163-2
USN-8179-1
USN-8179-2
USN-8179-3
USN-8179-4
USN-8184-1
USN-8185-1
USN-8185-2
USN-8203-1
USN-8204-1
USN-8243-1
USN-8258-1
USN-8260-1
USN-8261-1
USN-8265-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu
Rtl8723Bs