CVE-2026-90018
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr()
rtw_get_wps_attr() walks WPS attributes inside a WPS IE taken from a wireless management frame. For each candidate attribute it only checks that the fixed 4-byte attribute header (2-byte ID + 2-byte length) fits inside the IE:
attr_data_len (and therefore attr_len) is read directly from the wire and is never checked against the remaining bytes in the IE before being used as the size of:
Since attr_len is fully attacker controlled (0 to 65535+4), this is both a heap OOB read of wps_ie, and, more seriously, a stack buffer overflow at several call sites where buf_attr is a single-byte stack variable, e.g. rtw_get_wps_attr_content()'s callers passing WPS_ATTR_SELECTED_REGISTRAR into a stack "u8 sr"/"u8 selected_registrar" (drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c, drivers/staging/rtl8723bs/core/rtw_mlme_ext.c).
Leer descripción completaMostrar menos
A crafted WPS IE in a beacon or probe response processed during scanning can therefore smash the stack of the parsing thread.
rtw_get_wps_attr_content() itself has no independent length check and simply trusts the attr_len it gets back from rtw_get_wps_attr(), so fixing the bound here also fixes that caller.
The "attr_ptr + 4 > wps_ie + wps_ielen" header check above was added by commit 1463ca3ec6601 ("staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()"), which bounded the fixed header but never extended the check to cover the variable-length attribute data that follows it. Add that missing check before attr_len is used as a memcpy() length or accepted as a match.
Detalles técnicos trazas, registros y código del informe original
if (attr_ptr + 4 > wps_ie + wps_ielen) break; u16 attr_id = get_unaligned_be16(attr_ptr); u16 attr_data_len = get_unaligned_be16(attr_ptr + 2); u16 attr_len = attr_data_len + 4; memcpy(buf_attr, attr_ptr, attr_len);
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.52%
- Percentil entre todas las CVEs puntuadas: 42
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement85 % - Impacto principal
T1059.004Unix Shellexecution90 % - Impacto secundario
T1499.004Application or System Exploitationimpact75 %
Desbordamiento de pila mediante WPS IE malformado en tramas de gestión inalámbrica procesadas durante escaneo; permite ejecución de código o denegación de servicio.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/34f51d196c43a42046d229de5e79025d5ca553ca
- https://git.kernel.org/stable/c/3a6457ebf39080b87c712657fdb38f34a24fc3ff
- https://git.kernel.org/stable/c/931640dfcb8cfa08f6cfb46229716d8072356420
- https://git.kernel.org/stable/c/99aa998dec83ba180822f70e6d48a514fc81c20d
- https://git.kernel.org/stable/c/a53d1ac9ce63db07943b2b2248111003851fb00f
- https://git.kernel.org/stable/c/fd5e24ea8373347d0352f153a66e8647337d1b10
- https://git.kernel.org/stable/c/ff61aa3289355dafa811550a1764691cd1f5d33b
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90018",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"lessThan": "931640dfcb8cfa08f6cfb46229716d8072356420",
"versionType": "git"
},
{
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"lessThan": "3a6457ebf39080b87c712657fdb38f34a24fc3ff",
"versionType": "git"
},
{
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"lessThan": "fd5e24ea8373347d0352f153a66e8647337d1b10",
"versionType": "git"
},
{
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"lessThan": "a53d1ac9ce63db07943b2b2248111003851fb00f",
"versionType": "git"
},
{
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"lessThan": "ff61aa3289355dafa811550a1764691cd1f5d33b",
"versionType": "git"
},
{
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"lessThan": "34f51d196c43a42046d229de5e79025d5ca553ca",
"versionType": "git"
},
{
"status": "affected",
"version": "554c0a3abf216c991c5ebddcdb2c08689ecd290b",
"lessThan": "99aa998dec83ba180822f70e6d48a514fc81c20d",
"versionType": "git"
}
],
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_ieee80211.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.12",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.51",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.5",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/staging/rtl8723bs/core/rtw_ieee80211.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-16T11:17:14.647",
"references": [
{
"url": "https://git.kernel.org/stable/c/34f51d196c43a42046d229de5e79025d5ca553ca",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3a6457ebf39080b87c712657fdb38f34a24fc3ff",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/931640dfcb8cfa08f6cfb46229716d8072356420",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/99aa998dec83ba180822f70e6d48a514fc81c20d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a53d1ac9ce63db07943b2b2248111003851fb00f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fd5e24ea8373347d0352f153a66e8647337d1b10",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ff61aa3289355dafa811550a1764691cd1f5d33b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr()\n\nrtw_get_wps_attr() walks WPS attributes inside a WPS IE taken from\na wireless management frame. For each candidate attribute it only\nchecks that the fixed 4-byte attribute header (2-byte ID + 2-byte\nlength) fits inside the IE:\n\n\tif (attr_ptr + 4 > wps_ie + wps_ielen)\n\t\tbreak;\n\tu16 attr_id = get_unaligned_be16(attr_ptr);\n\tu16 attr_data_len = get_unaligned_be16(attr_ptr + 2);\n\tu16 attr_len = attr_data_len + 4;\n\nattr_data_len (and therefore attr_len) is read directly from the\nwire and is never checked against the remaining bytes in the IE\nbefore being used as the size of:\n\n\tmemcpy(buf_attr, attr_ptr, attr_len);\n\nSince attr_len is fully attacker controlled (0 to 65535+4), this is\nboth a heap OOB read of wps_ie, and, more seriously, a stack buffer\noverflow at several call sites where buf_attr is a single-byte\nstack variable, e.g. rtw_get_wps_attr_content()'s callers passing\nWPS_ATTR_SELECTED_REGISTRAR into a stack \"u8 sr\"/\"u8\nselected_registrar\" (drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c,\ndrivers/staging/rtl8723bs/core/rtw_mlme_ext.c). A crafted WPS IE in a\nbeacon or probe response processed during scanning can therefore\nsmash the stack of the parsing thread.\n\nrtw_get_wps_attr_content() itself has no independent length check\nand simply trusts the attr_len it gets back from rtw_get_wps_attr(),\nso fixing the bound here also fixes that caller.\n\nThe \"attr_ptr + 4 > wps_ie + wps_ielen\" header check above was added\nby commit 1463ca3ec6601 (\"staging: rtl8723bs: fix OOB reads in\nrtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()\"), which\nbounded the fixed header but never extended the check to cover the\nvariable-length attribute data that follows it. Add that missing\ncheck before attr_len is used as a memcpy() length or accepted as a\nmatch."
}
],
"lastModified": "2026-09-16T15:18:25.503",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}