← Volver al buscador de CVEs

CVE-2026-64145

Linux Kernel

Descripción

In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix dma_buffer leak on bus acquire failure wilc_wlan_firmware_download() allocates dma_buffer with kmalloc() at the top of the function and uses a -fail:- label to free it via kfree(dma_buffer) on error. All later error paths correctly use -goto fail- to route through this cleanup. However, the early failure path after the first acquire_bus() call uses a bare -return ret;-, which leaks dma_buffer whenever the bus acquire fails. Replace the early return with goto fail so the existing cleanup path runs. Found via a custom Coccinelle semantic patch hunting for kmalloc-d locals leaked on early-return error paths in driver firmware-download code.

EPSS 0.166%Riesgo 0
Ver fuente
Publicación
2026-07-19 16:17:56
Versiones afectadas
unknown
Tipo
Kernel
Última modificación
2026-07-30 14:59:47
Vector
Pending