CVE-2026-43387

Source
https://cve.org/CVERecord?id=CVE-2026-43387
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43387.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-43387
Downstream
Related
Published
2026-05-08T14:21:33.323Z
Modified
2026-07-21T09:52:50.231375086Z
Summary
staging: rtl8723bs: properly validate the data in rtw_get_ie_ex()
Details

In the Linux kernel, the following vulnerability has been resolved:

staging: rtl8723bs: properly validate the data in rtwgetie_ex()

Just like in commit 154828bf9559 ("staging: rtl8723bs: fix out-of-bounds read in rtwgetie() parser"), we don't trust the data in the frame so we should check the length better before acting on it

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43387.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
554c0a3abf216c991c5ebddcdb2c08689ecd290b
Fixed
ac38856092b4c994f94343251b30520bdeb7f475
Fixed
35969c3a208a07cb8642301df5869c34e2db7071
Fixed
8097a48c606a9306281ea7bd73bf2afc97553733
Fixed
740bca8bbdb707c0e4bb11e3316deb2f04fc7ce1
Fixed
821f7d759fb2de33c5e5b0c4981181c4d0c3e9b1
Fixed
6d62fa548387e159a21ea95132c09bfc96d336ed
Fixed
9a4cd4c37593cc8b8d28f9a6732b490a8032006a
Fixed
f0109b9d3e1e455429279d602f6276e34689750a

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43387.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.12.0
Fixed
5.10.253
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.203
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.167
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.130
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.78
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.19
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43387.json"