Executive brief
A vulnerability in the Realtek rtw88 Wi-Fi driver for Linux can cause system memory to leak when USB write operations fail. This typically occurs during hardware disconnection or when the system is under heavy memory pressure. Over time, these leaks can exhaust available system memory, potentially leading to system instability or a crash.
Technical details
A memory leak exists in the rtw88 USB driver (drivers/net/wireless/realtek/rtw88/usb.c) due to improper error handling in rtw_usb_write_port(). When this function fails to submit a USB Request Block (URB)—often due to ENOMEM or device disconnection—the completion callback that normally handles memory deallocation is never triggered. The calling functions, rtw_usb_write_data() and rtw_usb_tx_agg_skb(), previously ignored the return value of the write operation, resulting in leaked socket buffers (skbs) and transaction control blocks (txcb). An attacker or specific system conditions (like memory pressure) could trigger these failures to exhaust kernel memory. Patches have been released for various stable kernel branches to explicitly free these structures upon submission failure.
Affected products
- Linux Linux Kernel 6.2 to 6.18.38
Timeline
- 2026-05-18: other: Patch submitted by developer
- 2026-07-04: patched: Patch committed to stable tree
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/200d58c851b8f63f77a05570072dd20f79bc3681
- https://git.kernel.org/stable/c/2b2060c2075a72bc2de43ce5e1b9347d6c5e27bb
- https://git.kernel.org/stable/c/53fed4061a09755de99c89fdc7fae5b794da455f
- https://git.kernel.org/stable/c/6b964941bbfe6e0f18b1a5e008486dbb62df440a
- https://git.kernel.org/stable/c/8206d173d18ef5a077423119f4e9a93cb3a6f4eb