CVE-2026-64440
OOB write in Linux rtl8723bs Wi‑Fi driver via crafted 802.11 AssocResponse IE.
Is CVE-2026-64440 being exploited?
Not confirmed. CVE-2026-64440 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.27% probability of exploitation in the next 30 days.
How severe is CVE-2026-64440?
CVE-2026-64440 is rated High. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64440?
Yes. A fix has been recorded for CVE-2026-64440. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64440 affect?
CVE-2026-64440 affects Linux kernel (staging rtl8723bs Wi‑Fi driver), Devices using Realtek rtl8723bs chipset, Embedded systems/laptops with affected kernel versions. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64440?
Apply kernel update with rtl8723bs fix; avoid untrusted APs and update device firmware.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Malicious AP can cause up to 229-byte OOB kernel write, enabling kernel memory corruption leading to crash, privilege escalation, or possible RCE.
Immediate action required
- affected>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b and < 37f642d47c3648a707df3ceb092eee1adffbfd28
- affected>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b and < 8c872b47c7fc32e95e0da1db7512388794adcd69
- affected>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b and < bb3b942da4123b55d1cacf19d1a7d5ba15dbf83a
- affected>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b and < 918537a0fbed85aab61fa28ad75e6279070610c9
- affected>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b and < 6f91621fc45025ad3c0be796b70e6e4cee22fc69
- affected>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b and < 225b6d3fc7e99ac3d20b6c861d1e47d24e7ea31d
- affected>= 554c0a3abf216c991c5ebddcdb2c08689ecd290b and < f8001e1a516ba3b495728c65b61f799cbfad6bd0
- affected4.12
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.