CVE-2026-90018
CVE CVE-2026-90018EUVD EUVD-2026-80626Veröffentlicht 2026-09-16T10:33:23.000ZZuletzt geändert 2026-09-16T14:41:37.000ZCVSS 8.8
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() rtw_get_wps_attr() walks WPS attributes inside a WPS IE taken from a wireless management frame. For each candidate attribute it only checks that the fixed 4-byte attribute header (2-byte ID + 2-byte length) fits inside the IE: if (attr_ptr + 4 > wps_ie + wps_ielen) break; u16 attr_id = get_unaligned_be16(attr_ptr); u16 attr_data_len = get_unaligned_be16(attr_ptr + 2); u16 attr_len = attr_data_len + 4; attr_data_len (and therefore attr_len) is read directly from the wire and is never checked against the remaining bytes in the IE before being used as the size of: memcpy(buf_attr, attr_ptr, attr_len); Since attr_len is fully attacker controlled (0 to 65535+4), this is both a heap OOB read of wps_ie, and, more seriously, a stack buffer overflow at several call sites where buf_attr is a single-byte stack variable, e.g. rtw_get_wps_attr_content()'s callers passing WPS_ATTR_SELECTED_REGISTRAR into a stack "u8 sr"/"u8 selected_registrar" (drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c, drivers/staging/rtl8723bs/core/rtw_mlme_ext.c). A crafted WPS IE in a beacon or probe response processed during scanning can therefore smash the stack of the parsing thread. rtw_get_wps_attr_content() itself has no independent length check and simply trusts the attr_len it gets back from rtw_get_wps_attr(), so fixing the bound here also fixes that caller. The "attr_ptr + 4 > wps_ie + wps_ielen" header check above was added by commit 1463ca3ec6601 ("staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()"), which bounded the fixed header but never extended the check to cover the variable-length attribute data that follows it. Add that missing check before attr_len is used as a memcpy() length or accepted as a match.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux patch: 6.1.188; patch: 7.2.5; 554c0a3abf216c991c5ebddcdb2c08689ecd290b <fd5e24ea8373347d0352f153a66e8647337d1b10; patch: 6.18.51; patch: 0; 554c0a3abf216c991c5ebddcdb2c08689ecd290b <ff61aa3289355dafa811550a1764691cd1f5d33b; 554c0a3abf216c991c5ebddcdb2c08689ecd290b <99aa998dec83ba180822f70e6d48a514fc81c20d; patch: 5.15.221; 554c0a3abf216c991c5ebddcdb2c08689ecd290b <a53d1ac9ce63db07943b2b2248111003851fb00f; patch: 7.3-rc2; 554c0a3abf216c991c5ebddcdb2c08689ecd290b <3a6457ebf39080b87c712657fdb38f34a24fc3ff; patch: 6.12.110; 554c0a3abf216c991c5ebddcdb2c08689ecd290b <34f51d196c43a42046d229de5e79025d5ca553ca; 4.12; 554c0a3abf216c991c5ebddcdb2c08689ecd290b <931640dfcb8cfa08f6cfb46229716d8072356420; patch: 6.6.157
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.