CVE-2026-64440: staging: rtl8723bs: fix OOB write in HT_caps_handler()

Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:50:57 +0200
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026072538-CVE-2026-64440-7b48@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

staging: rtl8723bs: fix OOB write in HT_caps_handler()

HT_caps_handler() iterates pIE->length bytes and writes into
HT_caps.u.HT_cap[], which is a fixed 26-byte array (sizeof struct
HT_caps_element). Because pIE->length is a raw u8 from an over-the-air
802.11 AssocResponse frame and is never validated, a malicious AP can
set it up to 255, causing up to 229 bytes of out-of-bounds writes into
adjacent fields of struct mlme_ext_info.

Truncate the iteration count to the size of HT_caps.u.HT_cap using
umin() so that data from a longer-than-expected IE is silently ignored
rather than written out of bounds, preserving interoperability with APs
that pad the element. An early return on oversized IEs was considered
but rejected: it would bypass the pmlmeinfo->HT_caps_enable = 1
assignment that precedes the loop, silently disabling HT mode for APs
that append extra bytes to the HT Capabilities IE.

The Linux kernel CVE team has assigned CVE-2026-64440 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 4.12 with commit 554c0a3abf216c991c5ebddcdb2c08689ecd290b and fixed in 5.15.212 with commit 37f642d47c3648a707df3ceb092eee1adffbfd28
	Issue introduced in 4.12 with commit 554c0a3abf216c991c5ebddcdb2c08689ecd290b and fixed in 6.1.178 with commit 8c872b47c7fc32e95e0da1db7512388794adcd69
	Issue introduced in 4.12 with commit 554c0a3abf216c991c5ebddcdb2c08689ecd290b and fixed in 6.6.145 with commit bb3b942da4123b55d1cacf19d1a7d5ba15dbf83a
	Issue introduced in 4.12 with commit 554c0a3abf216c991c5ebddcdb2c08689ecd290b and fixed in 6.12.96 with commit 918537a0fbed85aab61fa28ad75e6279070610c9
	Issue introduced in 4.12 with commit 554c0a3abf216c991c5ebddcdb2c08689ecd290b and fixed in 6.18.39 with commit 6f91621fc45025ad3c0be796b70e6e4cee22fc69
	Issue introduced in 4.12 with commit 554c0a3abf216c991c5ebddcdb2c08689ecd290b and fixed in 7.1.4 with commit 225b6d3fc7e99ac3d20b6c861d1e47d24e7ea31d
	Issue introduced in 4.12 with commit 554c0a3abf216c991c5ebddcdb2c08689ecd290b and fixed in 7.2-rc3 with commit f8001e1a516ba3b495728c65b61f799cbfad6bd0

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64440
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/staging/rtl8723bs/core/rtw_wlan_util.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/37f642d47c3648a707df3ceb092eee1adffbfd28
	https://git.kernel.org/stable/c/8c872b47c7fc32e95e0da1db7512388794adcd69
	https://git.kernel.org/stable/c/bb3b942da4123b55d1cacf19d1a7d5ba15dbf83a
	https://git.kernel.org/stable/c/918537a0fbed85aab61fa28ad75e6279070610c9
	https://git.kernel.org/stable/c/6f91621fc45025ad3c0be796b70e6e4cee22fc69
	https://git.kernel.org/stable/c/225b6d3fc7e99ac3d20b6c861d1e47d24e7ea31d
	https://git.kernel.org/stable/c/f8001e1a516ba3b495728c65b61f799cbfad6bd0