PT-2026-98833 · Linux · Linux Kernel
CVE-2026-100076
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
Memory leaks occur in the rtl8723bs driver within the staging area of the Linux kernel. The functions
issue beacon(), issue probersp(), and issue asocrsp() use alloc mgtxmitframe() to obtain a management xmit frame and its associated xmit buf from fixed-size management-TX pools. In certain error or edge cases, the system returns early after allocation but before calling dump mgntframe(), which is responsible for transferring ownership and freeing the objects. Specifically, this happens when a beacon exceeds 512 bytes, when cur network->ie length exceeds MAX IE SZ, when kzalloc() for the SSID scratch buffer fails, or when pkt type is neither ASSOCRSP nor REASSOCRSP. Because these objects are removed from free lists without being placed on a pending list, they become orphaned and are only reclaimed during driver teardown. Repeated occurrences exhaust the management-TX pools, eventually causing alloc mgtxmitframe() to return NULL, which prevents the interface from sending beacons or probe/association responses.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel