Executive brief
A memory leak vulnerability was identified in the Linux kernel's USB (xHCI) driver. The xHCI driver is responsible for managing USB 3.0 connections. Under specific error conditions when disabling a USB slot, the system fails to properly release allocated memory, which could lead to a gradual depletion of system resources and potential instability or denial of service over time.
Technical details
A memory leak exists in the Linux kernel's USB xHCI driver within the xhci_disable_slot() function. The vulnerability is caused by improper error handling where the code calls kfree() on a command structure instead of xhci_free_command(). While kfree() releases the primary command structure, it fails to release the associated completion structure allocated by xhci_alloc_command(). An attacker or specific hardware failure conditions could trigger these error paths, leading to kernel memory exhaustion. The fix replaces kfree() with xhci_free_command() to ensure all associated structures are properly deallocated. This issue was identified via static analysis and affects mainline kernels up to v6.13-rc1.
Affected products
- Linux Linux Kernel v6.13-rc1 and earlier versions
Timeline
- 2026-03-05: other: Patch authored by Zilin Guan
- 2026-05-08: disclosed: CVE published
References
- https://git.kernel.org/stable/c/078b446efc0f5e496c31bccb72b98af979963a83
- https://git.kernel.org/stable/c/1e800e26d54ccf2ddf2ea6d6cbe021c804d8aa62
- https://git.kernel.org/stable/c/2e2baa8fb5aa4d080cbfeb84c51eff797529f413
- https://git.kernel.org/stable/c/46aea90763832cd6e9b0c2e1c00e6a9512156d4b
- https://git.kernel.org/stable/c/6288baf0c8c4dcfbf206773aede9c1f2269cec28
- https://git.kernel.org/stable/c/807e4fb5140c73eb5dba1e399a990db5c1f3cdf8
- https://git.kernel.org/stable/c/c1c8550e70401159184130a1afc6261db01fc0ce