CVE-2026-90016

Source
https://cve.org/CVERecord?id=CVE-2026-90016
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90016.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90016
Downstream
Related
Published
2026-09-16T10:33:22Z
Modified
2026-10-05T02:30:55Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H CVSS Calculator
Summary
staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()
Details

In the Linux kernel, the following vulnerability has been resolved:

staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()

rtw_restruct_wmm_ie() scans in_ie for a WMM IE with:

while (i < in_len) {
	...
	if (i + 5 < in_len && in_ie[i] == 0xDD && ...) {
		...
		break;
	}
	i += (in_ie[i + 1] + 2); /* to the next IE element */
}

When the "i + 5 < in_len" match check fails simply because i is within 5 bytes of the end of the buffer (i.e. no WMM IE was found near the tail of in_ie), execution falls through to "i += (in_ie[i + 1] + 2)", which reads in_ie[i + 1]. If i == in_len

  • 1 at that point, this is a 1-byte out-of-bounds read of an attacker-influenced IE buffer built from association/scan data.

Commit a75281626fc8f ("staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie") added the "i + 5 < in_len" guard to the match condition itself, but did not add an equivalent guard before the fallthrough advance, so the same class of OOB read remained reachable through the non-matching path.

Add an explicit bounds check before advancing to the next IE.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90016.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
554c0a3abf216c991c5ebddcdb2c08689ecd290b
Fixed
e63b72c5d7336981dfc05e5cb92becff29dfea00
Fixed
4420cc71841b50e31a7868ef7acb011c0e08d294
Fixed
fd19b8895f8a91087e8a62f1e27b128025dabb95
Fixed
28a289beaf226b30b1e6e7d7b1a2946fe2d6e852

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90016.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.12.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90016.json"