VDB
CVE-2026-31672
CVE-2026-31672
PUBLISHED
CVSS 9.300000190734863 CRITICAL
In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00usb: fix devres lifetime USB drivers bind to USB interfaces and any device managed resources should have their lifetime tied to the interface rather than parent USB device. This avoids issues like memory leaks when drivers are unbound without their devices being physically disconnected (e.g. on probe deferral or configuration changes). Fix the USB anchor lifetime so that it is released on driver unbind.
EPSS 0.02% · 3.4th percentile
Risk Scores
CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.02%
3.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | 7.0, 5.15.203, 6.1.169 |
| linux | linux_kernel | 4.7, 4.7, 4.7 |
Timeline
- Apr 24, 2026 CVE Published
- Apr 24, 2026 Security Advisory
- Apr 27, 2026 Security Advisory
- Apr 27, 2026 CVE Updated
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
References
- https://git.kernel.org/stable/c/64a457f6afbf15f984d95201a9a1e71eed3f9dd1 url
- https://git.kernel.org/stable/c/65518a6965d527c53013947031f26754f6a4f6af url
- https://git.kernel.org/stable/c/15b233e33b35b927bd8d0044c15325564ea1ba24 url
- https://git.kernel.org/stable/c/1de5c76bf40e9cdeebf54662f63011fb10fa452f url
- https://git.kernel.org/stable/c/b245db719bc7e57abf48bd5701662b270c3880f7 url
- https://git.kernel.org/stable/c/e360d15fcb1e819eef49e3d4434d8050542eed16 url
- https://git.kernel.org/stable/c/c99f198841b41735796e2ddfcd573783fb552eb9 url
- https://git.kernel.org/stable/c/25369b22223d1c56e42a0cd4ac9137349d5a898e url
- https://nvd.nist.gov/vuln/detail/CVE-2026-31672 advisory
- https://lists.debian.org/debian-lts-announce/2026/05/msg00004.html advisory
- https://lists.debian.org/debian-lts-announce/2026/05/msg00005.html advisory
- https://lists.debian.org/debian-security-announce/2026/msg00154.html advisory
- https://lists.debian.org/debian-security-announce/2026/msg00148.html advisory
- https://lists.debian.org/debian-lts-announce/2026/05/msg00051.html advisory
- https://lists.debian.org/debian-lts-announce/2026/05/msg00052.html advisory