Junglewise Threat Intelligence

CVE-2026-74678: Linux kernel ax88179_178a skb memory leak in tx_fixup

CVE-2026-74678 · Severity: high · CVSS 7.5 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's AX88179/178A USB network adapter driver leaks memory in its transmission data handling when network interface scatter-gather features are enabled and memory pressure causes linearization to fail. Under sustained network traffic with memory constraints, this leads to gradual memory exhaustion that can degrade system performance or trigger out-of-memory conditions.

Technical details

A memory leak exists in the ax88179_tx_fixup() function within the AX88179/178A USB network adapter driver. When NETIF_F_SG is enabled and skb_linearize() fails, the function returns NULL without freeing the socket buffer (skb), leaving the packet data allocated in memory. The calling usbnet_start_xmit() function cannot free the skb because it treats a NULL return as a drop signal and only frees if the local skb variable is non-NULL. This occurs under memory pressure when skb linearization fails. The fix adds dev_kfree_skb_any(skb) before the NULL return, consistent with similar error handling in the same function. Patches are available in the upstream Linux kernel.

Affected products

  • Linux Linux Kernel versions with commit 16b1c4e01c89 onwards (introducing the bug in TSO feature)

Timeline

  • 2026-08-22: disclosed: CVE published
  • 2026-08-03: patched: Upstream patch merged
  • 2026-08-19: patched: Backport to stable tree

References

Related threats