In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser The… (CVE-2025-68256)
A vulnerability in the Linux kernel's rtl8723bs staging driver was resolved. The rtw_get_ie() parser did not properly validate the length byte of Information Elements (IE), leading to out-of-bounds reads or potential infinite loops when processing malformed frames. The fix ensures the parser validates IE length against the remaining buffer before processing. This prevents memory safety issues caused by malformed frames.
AI Analysis
Technical Summary
The Linux kernel rtl8723bs staging driver contained a vulnerability in the rtw_get_ie() Information Element parser. The parser trusted the IE length byte without verifying that the IE data fits within the remaining frame buffer, allowing a malformed frame to cause out-of-bounds reads or infinite loops. The issue was fixed by adding validation to ensure the sum of the current offset, IE header, and IE length does not exceed the buffer limit before processing or advancing to the next IE. This prevents memory safety violations and ensures safe termination of the parser on malformed input.
Potential Impact
An attacker could send a malformed frame with an invalid IE length, causing the kernel driver to read beyond the buffer boundary or enter an infinite loop. This could lead to information disclosure, denial of service, or potentially code execution depending on the context. The CVSS 3.1 vector indicates high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix has been implemented that validates IE lengths before parsing, preventing out-of-bounds reads and infinite loops. Users should apply the official Linux kernel updates that include this patch once available. Patch status is not yet confirmed in this data; check the Linux kernel vendor advisory for current remediation guidance.
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser The… (CVE-2025-68256)
Description
A vulnerability in the Linux kernel's rtl8723bs staging driver was resolved. The rtw_get_ie() parser did not properly validate the length byte of Information Elements (IE), leading to out-of-bounds reads or potential infinite loops when processing malformed frames. The fix ensures the parser validates IE length against the remaining buffer before processing. This prevents memory safety issues caused by malformed frames.
CVSS v3.1
Score 8.8high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel rtl8723bs staging driver contained a vulnerability in the rtw_get_ie() Information Element parser. The parser trusted the IE length byte without verifying that the IE data fits within the remaining frame buffer, allowing a malformed frame to cause out-of-bounds reads or infinite loops. The issue was fixed by adding validation to ensure the sum of the current offset, IE header, and IE length does not exceed the buffer limit before processing or advancing to the next IE. This prevents memory safety violations and ensures safe termination of the parser on malformed input.
Potential Impact
An attacker could send a malformed frame with an invalid IE length, causing the kernel driver to read beyond the buffer boundary or enter an infinite loop. This could lead to information disclosure, denial of service, or potentially code execution depending on the context. The CVSS 3.1 vector indicates high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix has been implemented that validates IE lengths before parsing, preventing out-of-bounds reads and infinite loops. Users should apply the official Linux kernel updates that include this patch once available. Patch status is not yet confirmed in this data; check the Linux kernel vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-x52f-2whg-fhgm
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2025-68256"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a6b72d39c2644c7f8477feb
Added to database: 07/30/2026, 15:50:43 UTC
Last enriched: 07/30/2026, 18:40:50 UTC
Last updated: 09/10/2026, 19:38:46 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.