Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()

The skb passed to the rtw_hci_tx_write() is expected to be freed when
the function fails, but the error path in rtw_txq_push_skb() does not
free the skb before returning. This can lead to a memory leak in
rtw_txq_push() where a dequeued skb is passed to rtw_txq_push_skb().
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via memory exhaustion
Action: Assess Impact
AI Analysis

Impact

During transmission queue management in the rtw88 wifi driver skb() fails to free the socket buffer when an error occurs. This oversight allows a malicious driver invocation to accumulate unreleased memory in the kernel, gradually depleting available memory and impairing overall system performance. The resulting memory exhaustion can ultimately lead to kernel panics or degraded device operation, effectively causing denial of service.

Affected Systems

All Linux kernel releases that contain the rtw88 driver without the recent patch are affected, including distributions that ship a kernel built from mainline sources prior to the implementation of the fix. single vendor or version; any kernel integrating the rtw88 subsystem and executing errant packet pushes may be CVSS score is 4.7, indicating moderate severity. The EPSS score is < exploitation. The vulnerability is not. An attacker would need to trigger the error path within the rtw88 driver, typically through repeated packet transmission failures, to induce the memory leak. Consequently, the risk is moderate and mostly constrained to systems that rely heavily on the rtw88 wireless module.

Risk and Exploitability

The moderate CVSS score of 4.7 indicates medium impact, primarily a memory leak. The EPSS score is less than 1%, which points to a low probability of real‑world exploitation. Since the vulnerability is not in the CISA KEV catalog, there are no known active attacks. An attacker would have to force the rtw_txq_push_skb error path, likely through repeated packet failures, to accumulate memory pressure over time. Systems heavily relying on the rtw88 driver that experience frequent packet errors could suffer gradual memory exhaustion, potentially degrading kernel performance or causing instability.

Generated by OpenCVE AI on September 21, 2026 at 02:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the rtw88 memory leak fix (commit 51d8b355… or later).
  • If an upgrade is not immediately possible, disable the rtw88 wireless driver or restrict its use to trusted devices to prevent excessive memory consumption.
  • Monitor kernel memory usage and system stability to detect any signs of exhaustion caused by the driver.

Generated by OpenCVE AI on September 21, 2026 at 02:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() The skb passed to the rtw_hci_tx_write() is expected to be freed when the function fails, but the error path in rtw_txq_push_skb() does not free the skb before returning. This can lead to a memory leak in rtw_txq_push() where a dequeued skb is passed to rtw_txq_push_skb().
Title wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:04.339Z

Reserved: 2026-08-26T14:34:25.803Z

Link: CVE-2026-80941

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:18:59.227

Modified: 2026-09-14T13:18:50.160

Link: CVE-2026-80941

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:42:13Z

Links: CVE-2026-80941 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:00:12Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime