CVE-2026-64440

Source
https://cve.org/CVERecord?id=CVE-2026-64440
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64440.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64440
Downstream
Published
2026-07-25T08:51:13.138Z
Modified
2026-07-26T05:17:35.799777908Z
Summary
staging: rtl8723bs: fix OOB write in HT_caps_handler()
Details

In the Linux kernel, the following vulnerability has been resolved:

staging: rtl8723bs: fix OOB write in HTcapshandler()

HTcapshandler() iterates pIE->length bytes and writes into HTcaps.u.HTcap[], which is a fixed 26-byte array (sizeof struct HTcapselement). Because pIE->length is a raw u8 from an over-the-air 802.11 AssocResponse frame and is never validated, a malicious AP can set it up to 255, causing up to 229 bytes of out-of-bounds writes into adjacent fields of struct mlmeextinfo.

Truncate the iteration count to the size of HTcaps.u.HTcap using umin() so that data from a longer-than-expected IE is silently ignored rather than written out of bounds, preserving interoperability with APs that pad the element. An early return on oversized IEs was considered but rejected: it would bypass the pmlmeinfo->HTcapsenable = 1 assignment that precedes the loop, silently disabling HT mode for APs that append extra bytes to the HT Capabilities IE.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64440.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
554c0a3abf216c991c5ebddcdb2c08689ecd290b
Fixed
37f642d47c3648a707df3ceb092eee1adffbfd28
Fixed
8c872b47c7fc32e95e0da1db7512388794adcd69
Fixed
bb3b942da4123b55d1cacf19d1a7d5ba15dbf83a
Fixed
918537a0fbed85aab61fa28ad75e6279070610c9
Fixed
6f91621fc45025ad3c0be796b70e6e4cee22fc69
Fixed
225b6d3fc7e99ac3d20b6c861d1e47d24e7ea31d
Fixed
f8001e1a516ba3b495728c65b61f799cbfad6bd0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64440.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.12.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64440.json"