Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-74650

Published Aug 22, 2026 EPSS 0.18% (7th pctl)

Overview

CVE-2026-74650 is a known-severity vulnerability. It was published on August 22, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

staging: rtl8723bs: fix OOB read in WMM_param_handler()

WMM_param_handler() copies a fixed-size WMM parameter element out of a

received information element without checking that the element is long

enough, causing an out-of-bounds read for a short WMM IE.

The handler reads sizeof(struct WMM_para_element) (18) bytes at

pIE->data + 6, so it requires pIE->length to be at least 24

(WLAN_WMM_LEN), but it never validates the length. Two of its three

callers reach it after matching only the WMM OUI: OnAssocRsp() in

rtw_mlme_ext.c matches a 6-byte OUI, and join_cmd_hdl() matches a

4-byte OUI, before calling the handler. A vendor-specific IE carrying

the WMM OUI but a length between 6 and 23, placed in an association

response or in the IE blob handed to join_cmd_hdl(), passes the OUI

check and then makes the memcmp() and memcpy() at pIE->data + 6 read

past the end of the element. OnAssocRsp() parses a frame received from

the

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-74650?

CVE-2026-74650 is a known-severity vulnerability. It was published on August 22, 2026.

How severe is CVE-2026-74650?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-74650?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-74650?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-74650 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.