PT-2026-93521 · Linux · Linux Kernel

CVE-2026-89880

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the rtl2832 sdr media component where the rtl2832 sdr start streaming() function fails to release USB Request Blocks (URBs) and stream buffers during a failure. When rtl2832 sdr alloc urbs() succeeds but rtl2832 sdr submit urbs() fails, or when rtl2832 sdr alloc urbs() returns an out-of-memory error after rtl2832 sdr alloc stream bufs() has succeeded, the resources remain allocated. This leads to two defects during the subsequent VIDIOC STREAMON call: a permanent leak of coherent DMA memory because rtl2832 sdr alloc stream bufs() overwrites the buffer list, and a potential memory corruption issue where rtl2832 sdr alloc urbs() increments urbs initialized beyond MAX BULK BUFS, causing rtl2832 sdr free urbs() to read past the end of the urb list[] array and pass invalid pointers to usb free urb().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101604
CVE-2026-89880
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel