CVE-2025-71154
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/01/2026
Last modified:
26/02/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net: usb: rtl8150: fix memory leak on usb_submit_urb() failure<br />
<br />
In async_set_registers(), when usb_submit_urb() fails, the allocated<br />
async_req structure and URB are not freed, causing a memory leak.<br />
<br />
The completion callback async_set_reg_cb() is responsible for freeing<br />
these allocations, but it is only called after the URB is successfully<br />
submitted and completes (successfully or with error). If submission<br />
fails, the callback never runs and the memory is leaked.<br />
<br />
Fix this by freeing both the URB and the request structure in the error<br />
path when usb_submit_urb() fails.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 3.10.1 (including) | 5.10.248 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.198 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.160 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.120 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.64 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.4 (excluding) |
| cpe:2.3:o:linux:linux_kernel:3.10:-:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:3.10:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:3.10:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:3.10:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:3.10:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:3.10:rc7:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/12cab1191d9890097171156d06bfa8d31f1e39c8
- https://git.kernel.org/stable/c/151403e903840c9cf06754097b6732c14f26c532
- https://git.kernel.org/stable/c/2f966186b99550e3c665dbfb87b8314e30acea02
- https://git.kernel.org/stable/c/4bd4ea3eb326608ffc296db12c105f92dc2f2190
- https://git.kernel.org/stable/c/6492ad6439ff1a479fc94dc6052df3628faed8b6
- https://git.kernel.org/stable/c/a4e2442d3c48355a84463342f397134f149936d7
- https://git.kernel.org/stable/c/db2244c580540306d60ce783ed340190720cd429



