cbcvebase.
CVE-2025-68254
published 2025-12-16

CVE-2025-68254: In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix out-of-bounds read in OnBeacon ESR IE parsing The Extended…

PriorityP429high7.1CVSS 3.1
AVAACLPRNUINSUCLINAH
EPSS
0.25%
16.8th percentile
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix out-of-bounds read in OnBeacon ESR IE parsing The Extended Supported Rates (ESR) IE handling in OnBeacon accessed *(p + 1 + ielen) and *(p + 2 + ielen) without verifying that these offsets lie within the received frame buffer. A malformed beacon with an ESR IE positioned at the end of the buffer could cause an out-of-bounds read, potentially triggering a kernel panic. Add a boundary check to ensure that the ESR IE body and the subsequent bytes are within the limits of the frame before attempting to access them. This prevents OOB reads caused by malformed beacon frames.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < c03cb111628924827351e19baa5b073e9b0d723dc03cb111628924827351e19baa5b073e9b0d723d
linuxlinux>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < bb5940193d813449540d8d3a82abc045be41f48abb5940193d813449540d8d3a82abc045be41f48a
linuxlinux>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < c173ce97d3f0f0c0fefa39139d6d04ba60b5db22c173ce97d3f0f0c0fefa39139d6d04ba60b5db22
linuxlinux>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < d1ab7f9cee22e7b8a528da9ac953e4193b96cda5d1ab7f9cee22e7b8a528da9ac953e4193b96cda5
linuxlinux>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 38292407c2bb5b2b3131aaace4ecc7a829b40b7638292407c2bb5b2b3131aaace4ecc7a829b40b76
linuxlinux>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < bf323db1d883c209880bd92f3b12503e3531c3fcbf323db1d883c209880bd92f3b12503e3531c3fc
linuxlinux>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 502ddcc405b69fa92e0add6c1714d654504f6fd7502ddcc405b69fa92e0add6c1714d654504f6fd7
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.12-16.17.12-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 4.12.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.17.126.17.12
linuxlinux_kernel>= 6.18.0 < 6.18.16.18.1
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.626.12.62
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-3_on_azure_linux_3.0
ubuntulinux-aws-fips

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.