MEDIUM

CVE-2026-53107

Linux Linux Kernel 2026-06-24 CVSS v3.1
CVSS
5.5

Description

In the Linux kernel, the following vulnerability has been resolved:

wifi: libertas: don't kill URBs in interrupt context

Serialization for the TX path was enforced by calling
usb_kill_urb()/usb_kill_anchored_urbs(), to prevent transmission before
a previous URB was completed. usb_tx_block() can be called from
interrupt context (e.g. in the HCD giveback path), so we can't always
use it to kill in-flight URBs.

Prevent sleeping during interrupt context by checking the tx_submitted
anchor for existing URBs. We now return -EBUSY, to indicate there's
a pending request.

Summary dbcve.org

A race condition exists in the libertas WiFi driver where usb_kill_urb()/usb_kill_anchored_urbs() are called from interrupt context to enforce TX serialization. Since usb_tx_block() can be invoked from interrupt context (HCD giveback path), these blocking operations cannot be used. The fix checks the tx_submitted anchor for existing URBs and returns -EBUSY instead of attempting to kill in-flight URBs from interrupt context.

Mitigation

Update the Linux kernel to a version containing the fix for CVE-2026-53107. If running affected systems with libertas WiFi hardware, avoid triggering high TX load conditions until the patch is applied.

Patch Commit

EPSS Score

0.11%
Probability of exploitation in next 30 days
1.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE