wifi: rt2x00usb: fix devres lifetime
Summary
| CVE | CVE-2026-31672 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-04-24 15:16:47 UTC |
| Updated | 2026-04-24 17:51:40 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
wifi: rt2x00usb: fix devres lifetime
USB drivers bind to USB interfaces and any device managed resources
should have their lifetime tied to the interface rather than parent USB
device. This avoids issues like memory leaks when drivers are unbound
without their devices being physically disconnected (e.g. on probe
deferral or configuration changes).
Fix the USB anchor lifetime so that it is released on driver unbind. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 8b4c0009313f3d42e2540e3e1f776097dd0db73d 64a457f6afbf15f984d95201a9a1e71eed3f9dd1 git |
Not specified |
| CNA |
Linux |
Linux |
affected 8b4c0009313f3d42e2540e3e1f776097dd0db73d 65518a6965d527c53013947031f26754f6a4f6af git |
Not specified |
| CNA |
Linux |
Linux |
affected 8b4c0009313f3d42e2540e3e1f776097dd0db73d 15b233e33b35b927bd8d0044c15325564ea1ba24 git |
Not specified |
| CNA |
Linux |
Linux |
affected 8b4c0009313f3d42e2540e3e1f776097dd0db73d 1de5c76bf40e9cdeebf54662f63011fb10fa452f git |
Not specified |
| CNA |
Linux |
Linux |
affected 8b4c0009313f3d42e2540e3e1f776097dd0db73d b245db719bc7e57abf48bd5701662b270c3880f7 git |
Not specified |
| CNA |
Linux |
Linux |
affected 8b4c0009313f3d42e2540e3e1f776097dd0db73d e360d15fcb1e819eef49e3d4434d8050542eed16 git |
Not specified |
| CNA |
Linux |
Linux |
affected 8b4c0009313f3d42e2540e3e1f776097dd0db73d c99f198841b41735796e2ddfcd573783fb552eb9 git |
Not specified |
| CNA |
Linux |
Linux |
affected 8b4c0009313f3d42e2540e3e1f776097dd0db73d 25369b22223d1c56e42a0cd4ac9137349d5a898e git |
Not specified |
| CNA |
Linux |
Linux |
affected 4.7 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 4.7 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.253 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.203 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.169 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.135 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.82 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.23 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.19.13 6.19.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.0 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/e360d15fcb1e819eef49e3d4434d8050542eed16 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/b245db719bc7e57abf48bd5701662b270c3880f7 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/15b233e33b35b927bd8d0044c15325564ea1ba24 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/25369b22223d1c56e42a0cd4ac9137349d5a898e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/64a457f6afbf15f984d95201a9a1e71eed3f9dd1 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/c99f198841b41735796e2ddfcd573783fb552eb9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/65518a6965d527c53013947031f26754f6a4f6af |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/1de5c76bf40e9cdeebf54662f63011fb10fa452f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.