Executive brief
The Linux kernel's t7xx wireless WAN driver fails to properly clean up allocated DMA memory pools when initialization of data transmission and reception rings fails. This memory leak could accumulate over time if the driver encounters repeated initialization errors, gradually consuming system memory and potentially causing performance degradation or system instability on affected devices.
Technical details
A resource leak exists in the t7xx WWAN CLDMA (Control Low-level DMA) driver initialization code. The function t7xx_cldma_late_init() allocates a DMA pool (md_ctrl->gpd_dmapool) before initializing TX and RX rings. If either ring initialization fails, the error handling path frees the already-initialized rings but neglects to destroy the allocated DMA pool, leaving it allocated in memory. The fix adds explicit calls to dma_pool_destroy() and NULL-assignment in the error path to ensure proper resource cleanup. The vulnerability class is a resource leak (CWE-401) triggered during device initialization failure scenarios, with no authentication or network access required—it affects local kernel memory management during driver probe/initialization.
Affected products
- Linux Linux kernel Versions including t7xx WWAN driver prior to fix commit 2bd6f26d4ce1e87de4d736b1e8896daf3acf1c0e
Timeline
- 2026-06-24: disclosed: Fix committed upstream
- 2026-07-24: patched: Patch included in stable kernel releases