{"apiVersion":"1.0","identifier":"CVE-2026-74650","description":"In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in WMM_param_handler() WMM_param_handler() copies a fixed-size WMM parameter element out of a received information element without checking that the element is long enough, causing an out-of-bounds read for a short WMM IE. The handler reads sizeof(struct WMM_para_element) (18) bytes at pIE->data + 6, so it requires pIE->length to be at least 24 (WLAN_WMM_LEN), but it never validates the length. Two of its three callers reach it after matching only the WMM OUI: OnAssocRsp() in rtw_mlme_ext.c matches a 6-byte OUI, and join_cmd_hdl() matches a 4-byte OUI, before calling the handler. A vendor-specific IE carrying the WMM OUI but a length between 6 and 23, placed in an association response or in the IE blob handed to join_cmd_hdl(), passes the OUI check and then makes the memcmp() and memcpy() at pIE->data + 6 read past the end of the element. OnAssocRsp() parses a frame received from the AP, so this is reachable from a remote peer. The remaining caller in rtw_wlan_util.c already guards the handler with -pIE->length == WLAN_WMM_LEN-. Move the equivalent check into the handler itself so every caller is covered; the sibling IE handlers in the same parsing loop (HT_caps_handler(), HT_info_handler(), ERP_IE_handler()) likewise bound their accesses by pIE->length.","publishedAt":"2026-08-22T16:16:38","lastModifiedAt":"2026-08-27T13:18:35","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-74650","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00177,"riskScore":0,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-74650","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-74650","en":"https://www.redsauce.net/en/cves/CVE-2026-74650","fr":"https://www.redsauce.net/fr/cves/CVE-2026-74650","pt":"https://www.redsauce.net/pt/cves/CVE-2026-74650","de":"https://www.redsauce.net/de/cves/CVE-2026-74650","sk":"https://www.redsauce.net/sk/cves/CVE-2026-74650","el":"https://www.redsauce.net/el/cves/CVE-2026-74650"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-74650"}}