Memory Leak in Linux Kernel Affecting USB Firmware Download Path
CVE-2026-68410

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-68410?

A memory leak has been identified in the Linux kernel's firmware handling for the Libertas USB devices. Specifically, the function responsible for managing firmware downloads, helper_firmware_cb(), fails to deallocate memory for a single-stage firmware image after successfully loading it asynchronously. This oversight leads to unnecessary memory consumption during firmware operations. Although the bug was detected through experimental kernel analysis tools, runtime testing could not be conducted due to the absence of compatible Libertas USB hardware. A fix has been proposed to ensure that memory is released immediately following firmware loading.

Affected Version(s)

Linux 1dfba3060fe7ee03ccec25a91d35085142dfc295

Linux 1dfba3060fe7ee03ccec25a91d35085142dfc295

Linux 1dfba3060fe7ee03ccec25a91d35085142dfc295 < 6cda91bbb8dc3d22ef0323008a12dcf73a5129da

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.