CVE-2026-63821
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
19/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
wifi: rtw88: usb: fix memory leaks on USB write failures<br />
<br />
When rtw_usb_write_port() fails to submit a USB Request Block (URB)<br />
(e.g., due to device disconnect or ENOMEM), the completion callback is<br />
never executed.<br />
<br />
Currently, the driver ignores the return value of rtw_usb_write_port()<br />
in rtw_usb_write_data() and rtw_usb_tx_agg_skb(). Because these<br />
functions rely on the completion callback to free the socket buffers<br />
(skbs) and the transaction control block (txcb), a submission failure<br />
results in:<br />
1. A memory leak of the allocated skb in rtw_usb_write_data().<br />
2. A memory leak of the txcb structure and all aggregated skbs in<br />
rtw_usb_tx_agg_skb().<br />
<br />
Fix this by checking the return value of rtw_usb_write_port(). If it<br />
fails, explicitly free the skb in rtw_usb_write_data(), and properly<br />
purge the tx_ack_queue and free the txcb in rtw_usb_tx_agg_skb().<br />
<br />
The issue was discovered in practice during device disconnect/reconnect<br />
scenarios and memory pressure conditions. Tested by verifying normal TX<br />
operation continues after the fix without regressions.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/200d58c851b8f63f77a05570072dd20f79bc3681
- https://git.kernel.org/stable/c/2b2060c2075a72bc2de43ce5e1b9347d6c5e27bb
- https://git.kernel.org/stable/c/53fed4061a09755de99c89fdc7fae5b794da455f
- https://git.kernel.org/stable/c/6b964941bbfe6e0f18b1a5e008486dbb62df440a
- https://git.kernel.org/stable/c/8206d173d18ef5a077423119f4e9a93cb3a6f4eb



