Executive brief
The Linux kernel's rtw88 WiFi driver contains a memory leak in the transmit queue handling code. When the HCI (Host Controller Interface) write operation fails, the socket buffer is not properly freed, causing memory to accumulate over time. On systems experiencing frequent transmit failures, this can lead to gradual memory exhaustion and system instability.
Technical details
The vulnerability is a resource leak (CWE-400) in the rtw88 wireless driver's rtw_txq_push_skb() function. When rtw_hci_tx_write() fails, the function returns an error without freeing the socket buffer (skb) that was passed to it. The vulnerable code path is triggered when a dequeued skb in rtw_txq_push() is sent to rtw_txq_push_skb() and the HCI write operation fails. The fix adds an ieee80211_free_txskb() call in the error path before returning, ensuring proper cleanup. This is a local memory management issue affecting all affected kernel versions; no special privileges or network interaction is required, only that transmit failures occur during normal WiFi operation.
Affected products
- Linux Linux kernel Affected by commit aaab5d0e6737; patched in mainline and stable branches
Timeline
- 2026-07-27: disclosed: Initial patch submission by Abdun Nihaal
- 2026-09-07: patched: Patch merged to stable kernel tree
- 2026-09-11: advisory: CVE-2026-80941 published