5.5

CVE-2026-98160

staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init()

In the Linux kernel, the following vulnerability has been resolved:

staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init()

padapter->HalData is allocated via vzalloc(), but incorrectly freed
using kfree() in the rtw_sdio_if1_init() error path. Using kfree() to
release this vmalloc-backed buffer can lead to memory corruption.

Use rtw_hal_data_deinit() to pair the free correctly and free
HalData with vfree().

The bug was first flagged by an experimental static analysis tool we
are developing for kernel memory-management bugs. Manual inspection
confirms that the issue is still present in current mainline.

An x86_64 allyesconfig build showed no new warnings. As we do not have
suitable RTL8723BS SDIO hardware to test with, no runtime testing was
able to be performed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.12 < 5.10.270
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.221
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.188
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.157
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.110
Linux ≫ Linux Kernel Version >= 6.13 < 6.18.52
Linux ≫ Linux Kernel Version >= 6.19 < 7.2.6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.051
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-763 Release of Invalid Pointer or Reference

The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.

https://git.kernel.org/stable/c/ff6d1ba247b5c62bdb678f1069abc86ad88a1402
Patch
https://git.kernel.org/stable/c/d6158333d630a1b21d8914feaf77a6f5deb185d9
Patch
https://git.kernel.org/stable/c/6c017ab2b0e1b60b5be94636c94720347213d78b
Patch
https://git.kernel.org/stable/c/4520d673d49dabfd42c008a33889251025f7d6d5
Patch
https://git.kernel.org/stable/c/423574feaed192063ef0cd0813fb85425f39e539
Patch
https://git.kernel.org/stable/c/737c928ff5092d7e55128a232c231248fc993777
Patch
https://git.kernel.org/stable/c/911190f0b9511c3c81f2f2484414c1ae26f636b3
Patch
https://git.kernel.org/stable/c/264676418b726baca7be49171e306b6aa05cceb0
Patch