Back

MEDIUM

usbnet: fix memory leak in error case

Published Feb 26, 2025

Description

usbnet_write_cmd_async() mixed up which buffers need to be freed in which error case.

v2: add Fixes tag v3: fix uninitialized buf pointer

Affected products

Remediation

Red Hat statement

The bug could happen on error path for some specific cases of network links over USB being used. It leads to memory leak only, so the security impact is limited.

Red Hat mitigation

To mitigate this issue, prevent module usbnet from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Feb 26, 2025
Updated May 11, 2026
Reserved Feb 26, 2025
CISA Vulnrichment
Updated Oct 1, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 26, 2025