CVE-2026-31672: wifi: rt2x00usb: fix devres lifetime
In the Linux kernel, the following vulnerability has been resolved:
wifi: rt2x00usb: fix devres lifetime
USB drivers bind to USB interfaces and any device managed resources should have their lifetime tied to the interface rather than parent USB device. This avoids issues like memory leaks when drivers are unbound without their devices being physically disconnected (e.g. on probe deferral or configuration changes).
Fix the USB anchor lifetime so that it is released on driver unbind.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.137.1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31672?
The severity of CVE-2026-31672 is classified as medium due to its impact on the lifespan of device-managed resources in USB interfaces.
How do I fix CVE-2026-31672?
To fix CVE-2026-31672, you should update your Linux kernel to the latest version where this vulnerability has been resolved.
What type of vulnerability is CVE-2026-31672?
CVE-2026-31672 is a resource management vulnerability that affects USB drivers within the Linux kernel.
Which Linux kernel versions are affected by CVE-2026-31672?
CVE-2026-31672 affects certain versions of the Linux kernel that include the affected rt2x00usb driver module.
Who is the vendor associated with CVE-2026-31672?
The vendor associated with CVE-2026-31672 is the Linux kernel development community.