Impact
The rtl8192du wireless driver in the Linux kernel has a bug where memory allocated in rtl92du_init_shared_data() is not freed in any error path of rtl92du_init_sw_vars(), resulting in a memory leak, an instance of resource exhaustion (CWE‑772). The flaw permits the driver to consume increasing amounts of kernel memory over time, potentially exhausting system resources, degrading performance, or causing instability. The CVE entry details a patch that inserts a call to rtl92du_deinit_shared_data() in error paths to release the memory.
Affected Systems
All Linux systems that ship with the rtl8192du driver in the kernel and have not applied the upstream patch are affected. This includes any kernel version prior to the merge commit that introduced the fix. The vulnerability resides in the Wi‑Fi, which is part of the default kernel tree and may be loaded automatically on devices with compatible hardware.
Risk and Exploitability
The predictable impact is memory exhaustion, leading to possible denial‑of‑service if the driver is repeatedly loaded/unloaded or encounters errors. The CVSS score of 4.8 suggests moderate severity, while the EPSS score of <1% indicates a very low probability of exploitation under normal circumstances. The vulnerability is not listed in the CISA KEV catalog. An attacker would typically need to trigger repeated initialization errors on a vulnerable system, and there is no direct path to privilege escalation or arbitrary code execution.
OpenCVE Enrichment
Debian DSA