{"id":"CVE-2026-43387","summary":"staging: rtl8723bs: properly validate the data in rtw_get_ie_ex()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: properly validate the data in rtw_get_ie_ex()\n\nJust like in commit 154828bf9559 (\"staging: rtl8723bs: fix out-of-bounds\nread in rtw_get_ie() parser\"), we don't trust the data in the frame so\nwe should check the length better before acting on it","modified":"2026-07-22T18:22:40.804444339Z","published":"2026-05-08T14:21:33.323Z","related":["SUSE-SU-2026:3130-1","SUSE-SU-2026:3166-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43387.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/35969c3a208a07cb8642301df5869c34e2db7071"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6d62fa548387e159a21ea95132c09bfc96d336ed"},{"type":"WEB","url":"https://git.kernel.org/stable/c/740bca8bbdb707c0e4bb11e3316deb2f04fc7ce1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8097a48c606a9306281ea7bd73bf2afc97553733"},{"type":"WEB","url":"https://git.kernel.org/stable/c/821f7d759fb2de33c5e5b0c4981181c4d0c3e9b1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9a4cd4c37593cc8b8d28f9a6732b490a8032006a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ac38856092b4c994f94343251b30520bdeb7f475"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f0109b9d3e1e455429279d602f6276e34689750a"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43387.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43387"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"554c0a3abf216c991c5ebddcdb2c08689ecd290b"},{"fixed":"ac38856092b4c994f94343251b30520bdeb7f475"},{"fixed":"35969c3a208a07cb8642301df5869c34e2db7071"},{"fixed":"8097a48c606a9306281ea7bd73bf2afc97553733"},{"fixed":"740bca8bbdb707c0e4bb11e3316deb2f04fc7ce1"},{"fixed":"821f7d759fb2de33c5e5b0c4981181c4d0c3e9b1"},{"fixed":"6d62fa548387e159a21ea95132c09bfc96d336ed"},{"fixed":"9a4cd4c37593cc8b8d28f9a6732b490a8032006a"},{"fixed":"f0109b9d3e1e455429279d602f6276e34689750a"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43387.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.12.0"},{"fixed":"5.10.253"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.203"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.167"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.130"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.78"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.19"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"6.19.9"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43387.json"}}],"schema_version":"1.7.5"}