CVE-2026-68410

Source
https://cve.org/CVERecord?id=CVE-2026-68410
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68410.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-68410
Downstream
Published
2026-08-10T12:04:30Z
Modified
2026-08-21T03:30:11Z
Summary
wifi: libertas: fix memory leak in helper_firmware_cb()
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: libertas: fix memory leak in helper_firmware_cb()

helper_firmware_cb() neglects to free the single-stage firmware image after a successful async load, leading to a memory leak in the USB firmware-download path.

Fix this memory leak by calling release_firmware() immediately after lbs_fw_loaded() returns.

The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in the current wireless tree.

An x86_64 allyesconfig build showed no new warnings. As we do not have compatible Libertas USB hardware for exercising this firmware-download path, no runtime testing was able to be performed.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68410.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1dfba3060fe7ee03ccec25a91d35085142dfc295
Fixed
6c1f54a04813676c5a2150d99331c8d21f199374
Fixed
7f28722b3e4e0c8d49c859fea4a9b1fa13b5ae06
Fixed
ce829286f4935f1eb6b5dcb64da02910ce149c76
Fixed
d497b7566e74920acfe283dd6b2cbf1682890796
Fixed
eaeb1d74a47fc4864f2c754c0b9d654a9b7dc55c
Fixed
6cda91bbb8dc3d22ef0323008a12dcf73a5129da
Fixed
644640cde2fb216e6567de5eee780a38dbc95928
Fixed
63c2391deefb31e1b801b7f32bd502ca4808639b

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68410.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.13.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-68410.json"