Junglewise Threat Intelligence

CVE-2026-43255: Linux Kernel Libertas Wi-Fi driver race condition in usb_tx_block

CVE-2026-43255 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Libertas Wi-Fi driver could allow a local user to cause a system instability or crash. The issue occurs when the driver attempts to send data over USB too quickly, specifically during firmware loading, leading to internal kernel warnings and potential service disruptions. This affects systems using Marvell Libertas wireless adapters.

Technical details

A vulnerability exists in the 'libertas' Wi-Fi driver within the Linux kernel's USB interface (if_usb.c). The function 'usb_tx_block()' submits a USB Request Block (URB) without verifying if a previous transmission on that same URB has finished. If a subsequent call occurs while the URB is still active—a scenario likely during rapid firmware loading—'usb_submit_urb()' triggers a 'URB submitted while active' warning. This lack of serialization can lead to kernel instability. The fix involves calling 'usb_kill_urb()' before submitting new requests to ensure the URB is idle. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 2.6.22 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6

Timeline

  • 2026-05-06: disclosed
  • 2026-05-06: advisory
  • 2026-03-04: patched: Patches committed to various stable branches.

References

Related threats