Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-64446
Linux Linux — staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .0018 6.9 —
AFFECTED
Product Versions Fixed
Linux 554c0a3abf216c991c5ebddcdb2c08689ecd290b – —
Linux 4.12 – 5.10.261
TIMELINE
Jul 19 Reserved by Linux
Jul 25 Published (CNA: Linux)
Sep 3 ENRICHED — CVE-2026-64446 (Linux). Received CVSS 7.8 and CPE data from NVD.
Description
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()
supplicant_ie is a 256-byte array in struct security_priv. The WPA and
WPA2 IE copy paths use:
memcpy(padapter->securitypriv.supplicant_ie, &pwpa[0], wpa_ielen + 2);
where wpa_ielen is the raw IE length field (u8, 0-255). When a local user
supplies a connect request via nl80211 with a crafted WPA IE of length 255,
wpa_ielen + 2 equals 257, overflowing the 256-byte buffer by one byte into
the adjacent last_mic_err_time field.
rtw_parse_wpa_ie() does not prevent this: its length consistency check
compares *(wpa_ie+1) against (u8)(wpa_ie_len-2), which is (u8)(255) == 255
when wpa_ie_len = 257, so the check passes silently.
Add explicit bounds checks for both the WPA and WPA2 paths before the
memcpy, rejecting any IE whose total size (wpa_ielen + 2) exceeds the
supplicant_ie buffer.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| July 19, 2026 | Reserved | Reserved by Linux |
| July 25, 2026 | Published | Published (CNA: Linux) |
| September 3, 2026 | ENRICHED | ENRICHED — CVE-2026-64446 (Linux). Received CVSS 7.8 and CPE data from NVD. |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Linux | Linux | — | 554c0a3abf216c991c5ebddcdb2c08689ecd290b | — |
| Linux | Linux | — | 4.12 | 5.10.261 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-64446 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.