PatchSiren cyber security CVE debrief
CVE-2026-90016 Linux CVE debrief
A PatchSiren debrief of CVE-2026-90016, a HIGH severity vulnerability in the Linux kernel's rtl8723bs module. The vulnerability is caused by a 1-byte out-of-bounds read in the rtw_restruct_wmm_ie function. This issue can be triggered when the function scans for a WMM IE in the in_ie buffer and fails to find it near the end of the buffer, leading to a potential out-of-bounds read. The vulnerability requires verification of affected Linux kernel versions and prioritized patching. Linux kernel maintainers, Linux distribution maintainers, and users of affected Linux kernel versions should assess exposure and prioritize verification and patching.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-10-03
Who should care
Linux kernel maintainers, Linux distribution maintainers, and users of affected Linux kernel versions should assess exposure and prioritize verification and patching. The vulnerability requires verification of affected Linux kernel versions and prioritized patching. Operators of Linux kernel versions, platform administrators, and security teams should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor
Why it matters
CVE-2026-90016 is a HIGH severity vulnerability in the Linux kernel that requires verification of affected versions and prioritized patching.
- Verify if Linux kernel versions are affected by CVE-2026-90016
- Assess exposure of Linux kernel versions in use
- Apply patches or updates from the Linux kernel maintainers
Technical summary
The Linux kernel's rtl8723bs module has a 1-byte out-of-bounds read vulnerability due to a missing bounds check in the rtw_restruct_wmm_ie function. The function scans for a WMM IE in the in_ie buffer and fails to check for the bounds of the buffer, leading to a potential out-of-bounds read. This issue can be triggered when the function fails to find the WMM IE near the end of the buffer. The vulnerability requires verification of affected Linux kernel versions and prioritized patching. Defenders should assess exposure and prioritize verification of affected Linux kernel versions.
Defensive priority
Assess exposure and prioritize verification of affected Linux kernel versions.
Recommended defensive actions
- Assess exposure of Linux kernel versions in use
- Verify if Linux kernel versions are affected by CVE-2026-90016
- Apply patches or updates from the Linux kernel maintainers
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, which is a 1-byte out-of-bounds read in the Linux kernel's rtl8723bs module. The vulnerability is caused by a missing bounds check in the rtw_restruct_wmm_ie function. The function scans for a WMM IE in the in_ie buffer and fails to check for the bounds of the buffer, leading to a potential out-of-bounds read. Defenders should verify if Linux kernel versions are affected by CVE-2026-90016 and assess exposure of Linux kernel versions in use.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-90016 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-90016
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-90016 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90016
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/28a289beaf226b30b1e6e7d7b1a2946fe2d6e852
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4420cc71841b50e31a7868ef7acb011c0e08d294
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e63b72c5d7336981dfc05e5cb92becff29dfea00
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/fd19b8895f8a91087e8a62f1e27b128025dabb95
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.