PatchSiren cyber security CVE debrief
CVE-2026-100076 Linux CVE debrief
A vulnerability in the Linux kernel's rtl8723bs driver can cause memory leaks on error paths when handling management frames. This can lead to exhaustion of management-TX pools, potentially disrupting network operations. The vulnerability exists due to incorrect handling of management frames in the rtl8723bs driver, which can cause memory leaks and lead to denial-of-service conditions. Linux kernel maintainers, system administrators, and security teams should assess exposure and apply patches promptly to prevent potential denial-of-service conditions.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Linux kernel maintainers, system administrators, and security teams responsible for managing Linux-based systems using the rtl8723bs driver. These stakeholders should assess exposure and apply patches promptly to prevent potential denial-of-service conditions. Additionally, security teams should review system logs for potential denial-of-service conditions and monitor system configurations and kernel versions.
Why it matters
This vulnerability in the Linux kernel's rtl8723bs driver can cause memory leaks on error paths, potentially leading to denial-of-service conditions and disrupting network operations. Linux kernel maintainers, system administrators, and security teams should assess exposure and apply patches promptly.
- Potential denial-of-service conditions due to management-TX pool exhaustion.
- Disruption of network operations, particularly for systems relying on the rtl8723bs driver.
Technical summary
The Linux kernel's rtl8723bs driver has a vulnerability that can cause memory leaks on error paths when handling management frames. This can lead to exhaustion of management-TX pools, potentially disrupting network operations. The vulnerability exists due to incorrect handling of management frames in the rtl8723bs driver, which can cause memory leaks and lead to denial-of-service conditions. The vulnerability can be triggered by sending malformed management frames to the affected system. There is no evidence of public exploitation, but defenders should verify system logs
Defensive priority
Assess exposure and apply patches promptly to prevent potential denial-of-service conditions.
Recommended defensive actions
- Assess exposure by reviewing system configurations and kernel versions.
- Apply patches or updates provided by the Linux kernel maintainers.
- Monitor system logs for potential denial-of-service conditions.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information on affected systems and exploitation is limited. The vulnerability was introduced in the Linux kernel's rtl8723bs driver, which is used for managing RTL8723BS chipsets. The driver does not properly handle management frames, leading to memory leaks on error paths. The vulnerability can be triggered by sending malformed management frames to the affected system. There is no evidence of public exploitation, but defenders should verify system logs
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100076 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100076
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100076 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100076
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/41b8209376dffbd7b0b85c8bc4697d9166ac62ef
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6c9f6a3b9fdd31a0836b681053155b5997c0156e
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c48e5aa01525577d6b6e782962a5bfb0e1535cb5
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.