PT-2026-98833 · Linux · Linux Kernel

CVE-2026-100076

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description Memory leaks occur in the rtl8723bs driver within the staging area of the Linux kernel. The functions issue beacon(), issue probersp(), and issue asocrsp() use alloc mgtxmitframe() to obtain a management xmit frame and its associated xmit buf from fixed-size management-TX pools. In certain error or edge cases, the system returns early after allocation but before calling dump mgntframe(), which is responsible for transferring ownership and freeing the objects. Specifically, this happens when a beacon exceeds 512 bytes, when cur network->ie length exceeds MAX IE SZ, when kzalloc() for the SSID scratch buffer fails, or when pkt type is neither ASSOCRSP nor REASSOCRSP. Because these objects are removed from free lists without being placed on a pending list, they become orphaned and are only reclaimed during driver teardown. Repeated occurrences exhaust the management-TX pools, eventually causing alloc mgtxmitframe() to return NULL, which prevents the interface from sending beacons or probe/association responses.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-104450
CVE-2026-100076

Affected Products

Linux Kernel