PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-90016 Linux CVE debrief

A PatchSiren debrief of CVE-2026-90016, a HIGH severity vulnerability in the Linux kernel's rtl8723bs module. The vulnerability is caused by a 1-byte out-of-bounds read in the rtw_restruct_wmm_ie function. This issue can be triggered when the function scans for a WMM IE in the in_ie buffer and fails to find it near the end of the buffer, leading to a potential out-of-bounds read. The vulnerability requires verification of affected Linux kernel versions and prioritized patching. Linux kernel maintainers, Linux distribution maintainers, and users of affected Linux kernel versions should assess exposure and prioritize verification and patching.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-10-03
Advisory published
2026-09-16
Advisory updated
2026-10-03

Who should care

Linux kernel maintainers, Linux distribution maintainers, and users of affected Linux kernel versions should assess exposure and prioritize verification and patching. The vulnerability requires verification of affected Linux kernel versions and prioritized patching. Operators of Linux kernel versions, platform administrators, and security teams should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor

Why it matters

CVE-2026-90016 is a HIGH severity vulnerability in the Linux kernel that requires verification of affected versions and prioritized patching.

  • Verify if Linux kernel versions are affected by CVE-2026-90016
  • Assess exposure of Linux kernel versions in use
  • Apply patches or updates from the Linux kernel maintainers

Technical summary

The Linux kernel's rtl8723bs module has a 1-byte out-of-bounds read vulnerability due to a missing bounds check in the rtw_restruct_wmm_ie function. The function scans for a WMM IE in the in_ie buffer and fails to check for the bounds of the buffer, leading to a potential out-of-bounds read. This issue can be triggered when the function fails to find the WMM IE near the end of the buffer. The vulnerability requires verification of affected Linux kernel versions and prioritized patching. Defenders should assess exposure and prioritize verification of affected Linux kernel versions.

Defensive priority

Assess exposure and prioritize verification of affected Linux kernel versions.

Recommended defensive actions

  • Assess exposure of Linux kernel versions in use
  • Verify if Linux kernel versions are affected by CVE-2026-90016
  • Apply patches or updates from the Linux kernel maintainers
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, which is a 1-byte out-of-bounds read in the Linux kernel's rtl8723bs module. The vulnerability is caused by a missing bounds check in the rtw_restruct_wmm_ie function. The function scans for a WMM IE in the in_ie buffer and fails to check for the bounds of the buffer, leading to a potential out-of-bounds read. Defenders should verify if Linux kernel versions are affected by CVE-2026-90016 and assess exposure of Linux kernel versions in use.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-90016 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-90016

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-90016 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90016

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/28a289beaf226b30b1e6e7d7b1a2946fe2d6e852

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4420cc71841b50e31a7868ef7acb011c0e08d294

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e63b72c5d7336981dfc05e5cb92becff29dfea00

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/fd19b8895f8a91087e8a62f1e27b128025dabb95

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.