CVE-2026-53107
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: libertas: don't kill URBs in interrupt context
Serialization for the TX path was enforced by calling
usb_kill_urb()/usb_kill_anchored_urbs(), to prevent transmission before
a previous URB was completed. usb_tx_block() can be called from
interrupt context (e.g. in the HCD giveback path), so we can't always
use it to kill in-flight URBs.
Prevent sleeping during interrupt context by checking the tx_submitted
anchor for existing URBs. We now return -EBUSY, to indicate there's
a pending request.
Summary dbcve.org
A race condition exists in the libertas WiFi driver where usb_kill_urb()/usb_kill_anchored_urbs() are called from interrupt context to enforce TX serialization. Since usb_tx_block() can be invoked from interrupt context (HCD giveback path), these blocking operations cannot be used. The fix checks the tx_submitted anchor for existing URBs and returns -EBUSY instead of attempting to kill in-flight URBs from interrupt context.
Mitigation
Update the Linux kernel to a version containing the fix for CVE-2026-53107. If running affected systems with libertas WiFi hardware, avoid triggering high TX load conditions until the patch is applied.