-

CVE-2026-80940

wifi: rtw88: pci: fix resource leak on failed NAPI setup

In the Linux kernel, the following vulnerability has been resolved:

wifi: rtw88: pci: fix resource leak on failed NAPI setup

rtw_pci_probe() allocates PCI resources through
rtw_pci_setup_resource() before it sets up NAPI. If
rtw_pci_napi_init() fails, the error path jumps straight to
err_pci_declaim and skips rtw_pci_destroy(), leaving the PCI
resources allocated by rtw_pci_setup_resource() behind.

Add a dedicated cleanup label for the NAPI setup failure path so probe
destroys the PCI resources.

The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing current
mainline kernels. The tool is still under development and is not yet
publicly available. Manual inspection confirms that the bug is still
present in v7.1-rc7.

An x86_64 allyesconfig build showed no new warnings. As we do not have a
suitable rtw88 PCI board to test with, no runtime testing was able to be
performed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version d0bcb10e7b94861c714ab1e62c98bf8abaa37527
Version < 481fff9bda01720c70b19fb260808145a3f21594
Status affected
Version d0bcb10e7b94861c714ab1e62c98bf8abaa37527
Version < 34a505071d1ffc5ebf3dc3cd16d2a12b044bcc84
Status affected
Version d0bcb10e7b94861c714ab1e62c98bf8abaa37527
Version < b1596e212ab1739930b25b9d3daf6b5cd307b537
Status affected
Version d0bcb10e7b94861c714ab1e62c98bf8abaa37527
Version < e779df4806cd29cbcca5c9dc0a1073662c76b889
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.11
Status affected
Version 0
Version < 6.11
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/481fff9bda01720c70b19fb260808145a3f21594
https://git.kernel.org/stable/c/34a505071d1ffc5ebf3dc3cd16d2a12b044bcc84
https://git.kernel.org/stable/c/b1596e212ab1739930b25b9d3daf6b5cd307b537
https://git.kernel.org/stable/c/e779df4806cd29cbcca5c9dc0a1073662c76b889