SB20260812116 - Memory leak in Linux kernel marvell libertas driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Memory leak (CVE-ID: CVE-2026-68410)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a memory leak in helper_firmware_cb() in the libertas USB firmware-download path when handling an asynchronous firmware load. A local user can trigger the firmware-download path to cause a denial of service.
No runtime testing was performed because compatible Libertas USB hardware was unavailable.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/63c2391deefb31e1b801b7f32bd502ca4808639b
- https://git.kernel.org/stable/c/644640cde2fb216e6567de5eee780a38dbc95928
- https://git.kernel.org/stable/c/6cda91bbb8dc3d22ef0323008a12dcf73a5129da
- https://git.kernel.org/stable/c/d497b7566e74920acfe283dd6b2cbf1682890796
- https://git.kernel.org/stable/c/eaeb1d74a47fc4864f2c754c0b9d654a9b7dc55c