Back

HIGH

staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie

Published May 8, 2026

Description

The current code checks 'i + 5 < in_len' at the end of the if statement. However, it accesses 'in_ie[i + 5]' before that check, which can lead to an out-of-bounds read. Move the length check to the beginning of the conditional to ensure the index is within bounds before accessing the array.

Affected products

Remediation

No remediation recorded yet.

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published May 8, 2026
Updated May 11, 2026
Reserved May 1, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date May 8, 2026
ENISA EUVD
Assigner Linux
Published May 8, 2026
Updated May 11, 2026
Exploited since n/a
EUVD-2026-28692