Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-31604

CVE-2026-31604: Linux Kernel Privilege Escalation Flaw

CVE-2026-31604 is a privilege escalation vulnerability in the Linux Kernel's rtw88 WiFi driver that causes device reference leaks during probe failures. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-31604 Overview

A memory leak vulnerability has been identified in the Linux kernel's rtw88 WiFi driver. The vulnerability occurs when the driver fails to properly release USB device references during probe errors, such as when descriptor parsing fails. This flaw allows a local attacker with low privileges to cause a denial of service condition through memory exhaustion.

Critical Impact

Local attackers can exploit this memory leak vulnerability to exhaust system memory resources, potentially causing system instability or denial of service on affected Linux systems using rtw88-based WiFi adapters.

Affected Products

  • Linux Kernel (rtw88 WiFi driver component)
  • Systems using Realtek RTW88 USB WiFi adapters
  • Linux distributions shipping affected kernel versions

Discovery Timeline

  • 2026-04-24 - CVE-2026-31604 published to NVD
  • 2026-04-29 - Last updated in NVD database

Technical Details for CVE-2026-31604

Vulnerability Analysis

This vulnerability is classified as CWE-401 (Missing Release of Memory after Effective Lifetime), commonly referred to as a memory leak. The rtw88 WiFi driver takes a reference to the USB device structure during the probe phase but fails to release this reference on all error paths. When probe failures occur—for example, during descriptor parsing—the USB device reference count is not properly decremented.

The Linux driver core already maintains references to USB interfaces and their parent USB devices while bound to a driver. The additional reference taken by the rtw88 driver is redundant in normal operation. However, because it is not released on error conditions, repeated probe failures can lead to memory resources being leaked over time.

Root Cause

The root cause is improper reference counting in the rtw88 USB driver's probe function. When the driver encounters an error during initialization (such as a descriptor parsing failure), it exits the probe function without calling the appropriate function to release the USB device reference that was acquired earlier in the probe sequence. This creates an orphaned reference that prevents the kernel from reclaiming the associated memory.

Attack Vector

The attack vector for this vulnerability is local. An attacker with local access and low privileges could potentially trigger repeated probe failures by manipulating USB device connections or by exploiting other conditions that cause descriptor parsing to fail. Each failed probe attempt would leak memory, and over time, this could lead to memory exhaustion and system instability. The vulnerability does not require user interaction to exploit but does require physical or logical access to the system to initiate USB device operations.

The vulnerability mechanism involves the driver's failure to properly clean up resources on error paths. When usb_get_dev() is called to increment the reference count on the USB device, a corresponding usb_put_dev() must be called on all exit paths to ensure proper cleanup. The fix removes the redundant device reference entirely, as the driver core already manages these references appropriately.

Detection Methods for CVE-2026-31604

Indicators of Compromise

  • Unusual memory consumption growth over time on systems with rtw88 WiFi hardware
  • Kernel log messages indicating USB descriptor parsing failures in the rtw88 driver
  • System memory pressure alerts correlated with WiFi adapter probe events

Detection Strategies

  • Monitor kernel ring buffer (dmesg) for rtw88 driver probe failure messages
  • Implement memory usage monitoring and alerting for gradual memory consumption increases
  • Track USB device connection/disconnection events alongside memory metrics
  • Use kernel memory leak detection tools such as kmemleak during system testing

Monitoring Recommendations

  • Configure system monitoring to alert on sustained memory growth patterns
  • Enable verbose kernel logging for the rtw88 module during diagnostic periods
  • Implement periodic memory health checks on systems with affected WiFi hardware
  • Review system logs for patterns of repeated rtw88 probe failures

How to Mitigate CVE-2026-31604

Immediate Actions Required

  • Update to a patched Linux kernel version that includes the fix
  • If updates are not immediately available, consider temporarily disabling or removing rtw88 USB WiFi adapters from critical systems
  • Monitor affected systems for signs of memory exhaustion
  • Review and apply vendor security advisories for your Linux distribution

Patch Information

The Linux kernel development team has released patches to address this vulnerability. The fix removes the redundant USB device reference acquisition, ensuring that the driver no longer holds unnecessary references that could leak on probe failures. Multiple commits have been backported to stable kernel branches:

Workarounds

  • Blacklist the rtw88_usb module if the WiFi adapter is not required for operations
  • Use alternative WiFi hardware or drivers on critical systems until patches can be applied
  • Implement memory resource limits and monitoring to detect early signs of exhaustion
  • Schedule regular system reboots as a temporary measure to reclaim leaked memory
bash
# Temporarily blacklist the rtw88_usb module
echo "blacklist rtw88_usb" | sudo tee /etc/modprobe.d/blacklist-rtw88.conf
sudo update-initramfs -u
# Reboot required for changes to take effect

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.