cbcvebase.
CVE-2025-68256
published 2025-12-16

CVE-2025-68256: In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser The Information Element…

PriorityP345high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.25%
17.0th percentile
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser The Information Element (IE) parser rtw_get_ie() trusted the length byte of each IE without validating that the IE body (len bytes after the 2-byte header) fits inside the remaining frame buffer. A malformed frame can advertise an IE length larger than the available data, causing the parser to increment its pointer beyond the buffer end. This results in out-of-bounds reads or, depending on the pattern, an infinite loop. Fix by validating that (offset + 2 + len) does not exceed the limit before accepting the IE or advancing to the next element. This prevents OOB reads and ensures the parser terminates safely on malformed frames.

Affected

60 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 9829c6e1b2e4180fd18315252ad6faeab61280769829c6e1b2e4180fd18315252ad6faeab6128076
linuxlinux>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < b977eb31802817f4a37da95bf16bfdaa1eeb5fc2b977eb31802817f4a37da95bf16bfdaa1eeb5fc2
linuxlinux>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 30c558447e90935f0de61be181bbcedf75952e0030c558447e90935f0de61be181bbcedf75952e00
linuxlinux>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < a54e2b2db1b7de2e008b4f62eec35aaefcc663c5a54e2b2db1b7de2e008b4f62eec35aaefcc663c5
linuxlinux>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < df191dd9f4c7249d98ada55634fa8ac19089b8cbdf191dd9f4c7249d98ada55634fa8ac19089b8cb
linuxlinux>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < c0d93d69e1472ba75b78898979b90a98ba2a2501c0d93d69e1472ba75b78898979b90a98ba2a2501
linuxlinux>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 154828bf9559b9c8421fc2f0d7f7f76b3683aaed154828bf9559b9c8421fc2f0d7f7f76b3683aaed
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.12-16.17.12-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 4.12.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.17.126.17.12
linuxlinux_kernel>= 6.18.0 < 6.18.16.18.1
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.626.12.62
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv7.2HIGH
vendor_msrc7.5HIGH
vendor_ubuntu7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.