PatchSiren cyber security CVE debrief
CVE-2026-43387 Linux CVE debrief
This CVE addresses an out-of-bounds read vulnerability in the rtl8723bs staging driver within the Linux kernel. The flaw exists in the `rtw_get_ie_ex()` function, which failed to properly validate length fields in wireless frame data before processing. This vulnerability is conceptually similar to a prior fix in commit 154828bf9559 for the related `rtw_get_ie()` function. The issue affects multiple Linux kernel versions from 4.12 through 7.0 release candidates. Successful exploitation could lead to denial of service through local access. The vulnerability was resolved by implementing proper length validation checks before acting on frame data.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-08
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-05-08
- Advisory updated
- 2026-05-26
Who should care
Organizations running Linux systems with Realtek RTL8723BS wireless hardware, particularly embedded and IoT deployments. System administrators maintaining Linux kernels in the affected version ranges. Distributions shipping the rtl8723bs staging driver as a module.
Technical summary
The vulnerability exists in the `rtw_get_ie_ex()` function within the rtl8723bs staging driver, a Realtek RTL8723BS SDIO WiFi driver. The function parses wireless frame information elements without adequate validation of the length field, leading to potential out-of-bounds memory reads. The fix implements proper bounds checking before processing frame data, following the same pattern as a previous correction to the related `rtw_get_ie()` function. The rtl8723bs driver is typically used in embedded systems and IoT devices with SDIO-connected WiFi chipsets.
Defensive priority
medium
Recommended defensive actions
- Apply kernel updates to patched versions: 5.10.253 or later, 5.15.203 or later, 6.1.167 or later, 6.6.130 or later, 6.12.78 or later, 6.18.19 or later, 6.19.9 or later, or 7.0-rc4 or later
- Verify kernel version on systems using the rtl8723bs wireless driver
- Monitor vendor security advisories for distribution-specific kernel updates
- Consider disabling the rtl8723bs driver if not required for hardware functionality until patches can be applied
Evidence notes
The vulnerability description references commit 154828bf9559 as a comparable prior fix for `rtw_get_ie()`. The NVD record indicates this vulnerability affects Linux kernel versions 4.12 through 7.0-rc3 across multiple stable branches. Eight patch commits are referenced from kernel.org stable repositories. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) confirms local attack vector with low complexity and high availability impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43387 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43387
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43387 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43387
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/35969c3a208a07cb8642301df5869c34e2db7071
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6d62fa548387e159a21ea95132c09bfc96d336ed
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/740bca8bbdb707c0e4bb11e3316deb2f04fc7ce1
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8097a48c606a9306281ea7bd73bf2afc97553733
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/821f7d759fb2de33c5e5b0c4981181c4d0c3e9b1
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9a4cd4c37593cc8b8d28f9a6732b490a8032006a
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ac38856092b4c994f94343251b30520bdeb7f475
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.