CVE-2026-74650

Source
https://cve.org/CVERecord?id=CVE-2026-74650
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74650.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74650
Downstream
Published
2026-08-22T15:32:26Z
Modified
2026-08-28T03:47:13Z
Summary
staging: rtl8723bs: fix OOB read in WMM_param_handler()
Details

In the Linux kernel, the following vulnerability has been resolved:

staging: rtl8723bs: fix OOB read in WMM_param_handler()

WMM_param_handler() copies a fixed-size WMM parameter element out of a received information element without checking that the element is long enough, causing an out-of-bounds read for a short WMM IE.

The handler reads sizeof(struct WMM_para_element) (18) bytes at pIE->data + 6, so it requires pIE->length to be at least 24 (WLAN_WMM_LEN), but it never validates the length. Two of its three callers reach it after matching only the WMM OUI: OnAssocRsp() in rtw_mlme_ext.c matches a 6-byte OUI, and join_cmd_hdl() matches a 4-byte OUI, before calling the handler. A vendor-specific IE carrying the WMM OUI but a length between 6 and 23, placed in an association response or in the IE blob handed to join_cmd_hdl(), passes the OUI check and then makes the memcmp() and memcpy() at pIE->data + 6 read past the end of the element. OnAssocRsp() parses a frame received from the AP, so this is reachable from a remote peer.

The remaining caller in rtw_wlan_util.c already guards the handler with "pIE->length == WLAN_WMM_LEN". Move the equivalent check into the handler itself so every caller is covered; the sibling IE handlers in the same parsing loop (HT_caps_handler(), HT_info_handler(), ERP_IE_handler()) likewise bound their accesses by pIE->length.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74650.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
554c0a3abf216c991c5ebddcdb2c08689ecd290b
Fixed
5df2fd06567df5f178c8faae0bdaefd203618d21
Fixed
6cdca4c8b64c15a3ab9ad7a85f482e9519eadf93
Fixed
2bee6f7a0f0125238951e31da2e96d06fe359043
Fixed
1158b9931207392d6dd136aa0c4be18893b50fa1
Fixed
ce2399717de242344880044b91a20a712644fdfb
Fixed
e5b7610008f4e6a80c8b071aa77ddbd5e17ea472
Fixed
e429c6dfd5d2324cd866daaf4c29d5cfe4dea0e4
Fixed
ae21407350151bddfd4fea7aa39bd0643c0ca9d3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74650.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.12.0
Fixed
5.10.267
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.152
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.104
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.45
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74650.json"