PT-2025-51668 · Realtek+4 · Rtl8723Bs+4
Published
2025-11-27
·
Updated
2026-05-11
·
CVE-2025-68255
CVSS v2.0
7.7
High
| Vector | AV:A/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the Linux kernel related to the rtl8723bs driver. Specifically, a stack buffer overflow can occur during the parsing of Supported Rates Information Element (IE) within Association Request frames. A malicious station can exploit this by advertising an IE length exceeding 16 bytes, leading to a stack buffer overflow when copying data into a fixed-size 16-byte stack buffer. This issue can be triggered by malformed association requests, potentially causing kernel stack corruption. The vulnerability is addressed by clamping the IE length to the buffer size before copying and correcting bounds checks during the merging of Extended Supported Rates.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Ubuntu
Rtl8723Bs