Review reviewHigh

CVE-2025-68255

Linux

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix stack buffer overflow in OnAssocReq IE parsing The Supported Rates IE length from an incoming Association Request frame was used directly as the memcpy() length when copying into a fixed-size 16-byte stack buffer (supportRate). A malicious station can advertise an IE length larger than 16 bytes, causing a stack buffer overflow. Clamp ie_len to the buffer size before copying the Supported Rates IE, and correct the bounds check when merging Extended Supported Rates to prevent a second potential overflo...

CVSS
8.8
EPSS
0.34%
27.0% percentile
CISA KEV
Not listed
Published
2025.12.17
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.34%
Technical severityCVSS 8.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix stack buffer overflow in OnAssocReq IE parsing The Supported Rates IE length from an incoming Association Request frame was used directly as the memcpy() length when copying into a fixed-size 16-byte stack buffer (supportRate). A malicious station can advertise an IE length larger than 16 bytes, causing a stack buffer overflow. Clamp ie_len to the buffer size before copying the Supported Rates IE, and correct the bounds check when merging Extended Supported Rates to prevent a second potential overflo...

Affected product and versions

Product
Linux
Affected versions
>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 49b7806851f93fd342838c93f4f765e0cc5029b0, >= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 4445adedae770037078803d1ce41f9e88a1944b6, >= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < d129dc2a5d59b4d9cd2cc0b6eeb04df8461199f0, >= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 34620eb602aa432f090b2b784ee5c5070fb16cf9, >= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 61871c83259a511980ec2664964cecc69005398b, >= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 25411f5fcf5743131158f337c99c2bbf3f8477f5, >= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < e841d8ea722315b781c4fc5bf4f7670fbca88875, >= 554c0a3abf216c991c5ebddcdb2c08689ecd290b < 6ef0e1c10455927867cac8f0ed6b49f328f8cf95, >= 4.12
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available