CVE-2026-31672Disclosure(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00usb: fix devres lifetime USB drivers bind to USB interfaces and any device managed resources should have their lifetime tied to the interface rather than parent USB device. This avoids issues like memory leaks when drivers are unbound without their devices being physically disconnected (e.g. on probe deferral or configuration changes). Fix the USB anchor lifetime so that it is released on driver unbind.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-401

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-24); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-24: 2Mentions · 2026-04-26: 1Patch / Workaround · 2026-04-24: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-26: 104-2404-26
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-242
Disclosure1Patch1
2026-04-261
Disclosure1
Full discourse3 posts
  • WindowsForum@windowsforum
    Disclosure

    🪟 Memory leak CVE in a Wi‑Fi driver? Not flashy like RCE, but it’s the sneaky “performance death by a thousand cuts” bug. In WSL/Windows land, leaks still become incidents fast. https://windowsforum.com/threads/cve-2026-31672-rt2x00usb-linux-wi-fi-driver-memory-leak-triage-for-windows-wsl-teams.415193/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LinuxKernelSecurity #Rt2X00UsbDriver #UsbDeviceCleanup #HybridPatchManagement

    Post summary

    A memory‑leak vulnerability (CVE‑2026‑31672) in the rt2x00usb Wi‑Fi driver is disclosed; no evidence of exploitation, PoC, or patch is provided in the text.

    00000165
    1.1K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31672 In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00usb: fix devres lifetime USB drivers bind to USB interfaces and any device managed r… https://www.cve.org/CVERecord?id=CVE-2026-31672

    Post summary

    The CVE has been addressed with a patch; no exploit, work‑arounds or active exploitation details are provided.

    0000052
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31672 USB Anchor Devres Lifetime Issue in Linux Kernel rt2x00usb Driver https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31672

    Post summary

    The post announces CVE‑2026‑31672, a lifetime issue impacting the USB anchor devres subsystem of the Linux rt2x00usb driver, and links to a vulnerability details page.

    0000030
    4.0K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel4.7--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more