{"id":"CVE-2026-46305","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: os_dep: avoid NULL pointer dereference in rtw_cbuf_alloc\n\nThe return value of kzalloc_flex() is used without\nensuring that the allocation succeeded,…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: os_dep: avoid NULL pointer dereference in rtw_cbuf_alloc\n\nThe return value of kzalloc_flex() is used without\nensuring that the allocation succeeded,…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-476"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 7.0, < 7.0.7","linux_kernel = 7.1"],"patched":["linux_kernel 7.0.7"],"published":"2026-06-08","updated":"2026-09-14","sourceUpdated":"2026-09-14T12:17:42.407","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-46305","references":[{"url":"https://git.kernel.org/stable/c/0a5f411becfb7c57aa89827213d31ef23a03d75a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d4024037ee309a8f0cb86b4093d59da0e135db8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc851db06045a40c18233dd76ef0562d7f8bb6db","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"epss":0.00112,"epssPercentile":0.01581,"ingestedAt":"2026-07-08T12:51:00.699Z","slug":"CVE-2026-46305","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8723bs: os_dep: avoid NULL pointer dereference in rtw_cbuf_alloc\n\nThe return value of kzalloc_flex() is used without\nensuring that the allocation succeeded, and the\npointer is dereferenced unconditionally.\n\nGuard the access to the allocated structure to\navoid a potential NULL pointer dereference if the\nallocation fails.\n\n## Affected\n\n- `linux_kernel >= 7.0, < 7.0.7`\n- `linux_kernel = 7.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 7.0.7`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":201693,"id":"CVE-2026-46305","ts":1789399606640,"field":"cvss","old":null,"new":"5.5"},{"seq":201692,"id":"CVE-2026-46305","ts":1789399606640,"field":"severity","old":"none","new":"medium"},{"seq":200425,"id":"CVE-2026-46305","ts":1789397230064,"field":"cvss","old":"5.5","new":null},{"seq":200424,"id":"CVE-2026-46305","ts":1789397230064,"field":"severity","old":"medium","new":"none"},{"seq":198349,"id":"CVE-2026-46305","ts":1789391858512,"field":"cvss","old":null,"new":"5.5"},{"seq":198348,"id":"CVE-2026-46305","ts":1789391858512,"field":"severity","old":"none","new":"medium"}]}