Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars()

The memory allocated inside rtl92du_init_shared_data() is not freed in
any of the subsequent error paths in rtl92du_init_sw_vars().
Fix that by adding a call to rtl92du_deinit_shared_data() in the error
path.
Published: 2026-09-11
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak
Action: Apply Patch
AI Analysis

Impact

The rtl8192du wireless driver in the Linux kernel has a bug where memory allocated in rtl92du_init_shared_data() is not freed in any error path of rtl92du_init_sw_vars(), resulting in a memory leak, an instance of resource exhaustion (CWE‑772). The flaw permits the driver to consume increasing amounts of kernel memory over time, potentially exhausting system resources, degrading performance, or causing instability. The CVE entry details a patch that inserts a call to rtl92du_deinit_shared_data() in error paths to release the memory.

Affected Systems

All Linux systems that ship with the rtl8192du driver in the kernel and have not applied the upstream patch are affected. This includes any kernel version prior to the merge commit that introduced the fix. The vulnerability resides in the Wi‑Fi, which is part of the default kernel tree and may be loaded automatically on devices with compatible hardware.

Risk and Exploitability

The predictable impact is memory exhaustion, leading to possible denial‑of‑service if the driver is repeatedly loaded/unloaded or encounters errors. The CVSS score of 4.8 suggests moderate severity, while the EPSS score of <1% indicates a very low probability of exploitation under normal circumstances. The vulnerability is not listed in the CISA KEV catalog. An attacker would typically need to trigger repeated initialization errors on a vulnerable system, and there is no direct path to privilege escalation or arbitrary code execution.

Generated by OpenCVE AI on September 21, 2026 at 03:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that adds a deallocation call in rtl92du_init_sw_vars() to release shared data on error paths.
  • Upgrade the kernel to a release that includes the patch (any version built after the merge commit that fixes the leak).
  • If an upgrade to the rtl8192du module is not possible, prevent it from loading (for example, add ‘blacklist rtl8192du’ to /etc/modprobe.d/blacklist.conf and reboot).

Generated by OpenCVE AI on September 21, 2026 at 03:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() The memory allocated inside rtl92du_init_shared_data() is not freed in any of the subsequent error paths in rtl92du_init_sw_vars(). Fix that by adding a call to rtl92du_deinit_shared_data() in the error path.
Title wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:42:14.589Z

Reserved: 2026-08-26T14:34:25.803Z

Link: CVE-2026-80942

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:18:59.660

Modified: 2026-09-11T20:18:59.660

Link: CVE-2026-80942

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:42:14Z

Links: CVE-2026-80942 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:00:13Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime