PT-2026-64661 · Linux · Linux

CVE-2026-64440

·

Published

2026-07-25

·

Updated

2026-07-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix OOB write in HT caps handler()
HT caps handler() iterates pIE->length bytes and writes into HT caps.u.HT cap[], which is a fixed 26-byte array (sizeof struct HT caps element). Because pIE->length is a raw u8 from an over-the-air 802.11 AssocResponse frame and is never validated, a malicious AP can set it up to 255, causing up to 229 bytes of out-of-bounds writes into adjacent fields of struct mlme ext info.
Truncate the iteration count to the size of HT caps.u.HT cap using umin() so that data from a longer-than-expected IE is silently ignored rather than written out of bounds, preserving interoperability with APs that pad the element. An early return on oversized IEs was considered but rejected: it would bypass the pmlmeinfo->HT caps enable = 1 assignment that precedes the loop, silently disabling HT mode for APs that append extra bytes to the HT Capabilities IE.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64440

Affected Products

Linux