CVE-2025-68255

Source
https://cve.org/CVERecord?id=CVE-2025-68255
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68255.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-68255
Downstream
Related
Published
2025-12-16T14:44:58.031Z
Modified
2026-03-20T12:46:19.913569Z
Summary
staging: rtl8723bs: fix stack buffer overflow in OnAssocReq IE parsing
Details

In the Linux kernel, the following vulnerability has been resolved:

staging: rtl8723bs: fix stack buffer overflow in OnAssocReq IE parsing

The Supported Rates IE length from an incoming Association Request frame was used directly as the memcpy() length when copying into a fixed-size 16-byte stack buffer (supportRate). A malicious station can advertise an IE length larger than 16 bytes, causing a stack buffer overflow.

Clamp ie_len to the buffer size before copying the Supported Rates IE, and correct the bounds check when merging Extended Supported Rates to prevent a second potential overflow.

This prevents kernel stack corruption triggered by malformed association requests.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68255.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
554c0a3abf216c991c5ebddcdb2c08689ecd290b
Fixed
49b7806851f93fd342838c93f4f765e0cc5029b0
Fixed
4445adedae770037078803d1ce41f9e88a1944b6
Fixed
d129dc2a5d59b4d9cd2cc0b6eeb04df8461199f0
Fixed
34620eb602aa432f090b2b784ee5c5070fb16cf9
Fixed
61871c83259a511980ec2664964cecc69005398b
Fixed
25411f5fcf5743131158f337c99c2bbf3f8477f5
Fixed
e841d8ea722315b781c4fc5bf4f7670fbca88875
Fixed
6ef0e1c10455927867cac8f0ed6b49f328f8cf95

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68255.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.12.0
Fixed
5.10.248
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.198
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.160
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.120
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.62
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.12
Type
ECOSYSTEM
Events
Introduced
6.18.0
Fixed
6.18.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68255.json"