Impact
The rtl2832_sdr_start_streaming() function allocates asynchronous request blocks (URBs) and stream buffers before submitting them for USB transmission. If allocation succeeds but submission fails, or allocation fails after stream buffers have been allocated, the code fails to release the allocated resources. This leads to memory leaks and subsequent erroneous state. When a second streaming request is attempted, the earlier leak causes the urb_initialized counter to exceed the maximum bulk buffer count, resulting in a processing loop that reads past the end of the urb_list array and passes garbage pointers to usb_free_urb(), which can corrupt kernel memory or cause a crash. The likely attack vector is local control of the RTL2832 SDR device, with an attacker able to trigger repeated start_stream calls to exhaust memory or destabilize the kernel. The impact is a denial of service via kernel crash or instability.
Affected Systems
The vulnerability exists in the Linux kernel's rtl2832_sdr driver, used for RTL2832-based software defined radio (SDR) devices. No specific kernel release or patch level is disclosed in the advisory, so any Linux kernel version containing the vulnerable rtl2832_sdr code may be affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity issue, while the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The vulnerability is not yet listed in the CISA KEV catalog. The bug requires local access to the SDR hardware and knowledge of the driver’s streaming API, meaning attackers are limited to privileged users or those with physical access to the device. Nonetheless, the failure to properly release resources can be leveraged to exhaust memory or corrupt kernel memory, providing a robust denial-of-service route.
OpenCVE Enrichment
Debian DLA
Debian DSA