CVE-2025-68255

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix stack buffer overflow in OnAssocReq IE parsing The Supported Rates IE length from an incoming Association Request frame was used directly as the memcpy() length when copying into a fixed-size 16-byte stack buffer (supportRate). A malicious station can advertise an IE length larger than 16 bytes, causing a stack buffer overflow. Clamp ie_len to the buffer size before copying the Supported Rates IE, and correct the bounds check when merging Extended Supported Rates to prevent a second potential overflow. This prevents kernel stack corruption triggered by malformed association requests.
Configurations

No configuration.

History

30 Jul 2026, 06:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

19 Jan 2026, 13:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/4445adedae770037078803d1ce41f9e88a1944b6 -
  • () https://git.kernel.org/stable/c/49b7806851f93fd342838c93f4f765e0cc5029b0 -

11 Jan 2026, 17:15

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/34620eb602aa432f090b2b784ee5c5070fb16cf9 -
  • () https://git.kernel.org/stable/c/d129dc2a5d59b4d9cd2cc0b6eeb04df8461199f0 -

16 Dec 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-16 15:15

Updated : 2026-07-30 06:24


NVD link : CVE-2025-68255

Mitre link : CVE-2025-68255

CVE.ORG link : CVE-2025-68255


JSON object : View

Products Affected

No product.

CWE

No CWE.