CVE-2026-31672

Source
https://cve.org/CVERecord?id=CVE-2026-31672
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31672.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-31672
Downstream
Published
2026-04-24T14:45:19.725Z
Modified
2026-04-25T04:20:39.617429Z
Summary
wifi: rt2x00usb: fix devres lifetime
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: rt2x00usb: fix devres lifetime

USB drivers bind to USB interfaces and any device managed resources should have their lifetime tied to the interface rather than parent USB device. This avoids issues like memory leaks when drivers are unbound without their devices being physically disconnected (e.g. on probe deferral or configuration changes).

Fix the USB anchor lifetime so that it is released on driver unbind.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31672.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8b4c0009313f3d42e2540e3e1f776097dd0db73d
Fixed
64a457f6afbf15f984d95201a9a1e71eed3f9dd1
Fixed
65518a6965d527c53013947031f26754f6a4f6af
Fixed
15b233e33b35b927bd8d0044c15325564ea1ba24
Fixed
1de5c76bf40e9cdeebf54662f63011fb10fa452f
Fixed
b245db719bc7e57abf48bd5701662b270c3880f7
Fixed
e360d15fcb1e819eef49e3d4434d8050542eed16
Fixed
c99f198841b41735796e2ddfcd573783fb552eb9
Fixed
25369b22223d1c56e42a0cd4ac9137349d5a898e

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31672.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.7.0
Fixed
5.10.253
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.203
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.169
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.135
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.82
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.23
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.13

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31672.json"