Description
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix out-of-bounds read in OnBeacon ESR IE parsing The Extended Supported Rates (ESR) IE handling in OnBeacon accessed *(p + 1 + ielen) and *(p + 2 + ielen) without verifying that these offsets lie within the received frame buffer. A malformed beacon with an ESR IE positioned at the end of the buffer could cause an out-of-bounds read, potentially triggering a kernel panic. Add a boundary check to ensure that the ESR IE body and the subsequent bytes are within the limits of the frame before attempting to access them. This prevents OOB reads caused by malformed beacon frames.
Product status
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before d1ab7f9cee22e7b8a528da9ac953e4193b96cda5
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 38292407c2bb5b2b3131aaace4ecc7a829b40b76
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before bf323db1d883c209880bd92f3b12503e3531c3fc
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 502ddcc405b69fa92e0add6c1714d654504f6fd7
6.12.62 (semver)
6.17.12 (semver)
6.18.1 (semver)
6.19-rc1 (original_commit_for_fix)
References
git.kernel.org/...c/d1ab7f9cee22e7b8a528da9ac953e4193b96cda5
git.kernel.org/...c/38292407c2bb5b2b3131aaace4ecc7a829b40b76
git.kernel.org/...c/bf323db1d883c209880bd92f3b12503e3531c3fc
git.kernel.org/...c/502ddcc405b69fa92e0add6c1714d654504f6fd7
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.