CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64445

highCVSS 8.8covered by 2 sourcesfirst seen 2026-07-14
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() OnAuth() has two bugs in the shared-key authentication path. When the Privacy bit is set, rtw_wep_decrypt() is called without verifying that the frame is long enough to contain a valid WEP IV and ICV. Inside rtw_wep_decrypt(), length is computed as: length = len - WLAN_HDR_A3_LEN - iv_len and then passed as (length - 4) to crc32_le(). If len is less than WLAN_HDR_A3_LEN + iv_len + icv_len (32 bytes), length - 4 is negative and, after the implicit cast to size_t, causes crc32_le() to read far beyond the frame buffer. Add a minimum length check before accessing the IV field and calling the decryption path. When processing a seq=3 response, rtw_get_ie() stores the Challenge Text IE length in ie_len, but the subsequent memcmp() always reads 128 bytes regardless of ie_len. IEEE 802.11 mandates a challenge text of exactly 128 bytes; reject any IE whose length field differs, matching the check already applied to OnAuthClient().

CSIRTS triage

What
There is a fix for a WEP length underflow and out-of-bounds read in the OnAuth() function.
Who is affected
Deployments using the rtl8723bs driver are affected.
Urgency
Remediation is necessary to prevent potential exploitation, although exploitation status is currently unknown.
Action
Apply the fix for CVE-2026-64445.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-64445

Get an email if CVE-2026-64445 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-64445

CVE.org record

Embed the live status

CVE-2026-64445 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64445 status](https://www.csirts.com/badge/CVE-2026-64445)](https://www.csirts.com/cve/CVE-2026-64445)