Unrated severityNVD Advisory· Published Jun 8, 2026
CVE-2026-46305
CVE-2026-46305
Description
In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: os_dep: avoid NULL pointer dereference in rtw_cbuf_alloc
The return value of kzalloc_flex() is used without ensuring that the allocation succeeded, and the pointer is dereferenced unconditionally.
Guard the access to the allocated structure to avoid a potential NULL pointer dereference if the allocation fails.
Affected products
4- osv-coords2 versions
>= 7.0.0, < 7.0.7+ 1 more
- (no CPE)range: >= 7.0.0, < 7.0.7
- (no CPE)range: < 7.0.12-1.1
Patches
Vulnerability mechanics
References
2News mentions
1- Linux Kernel: 25 Vulnerabilities Disclosed in Single Batch on June 8, 2026Vypr Intelligence · Jun 8, 2026