CVE-2026-53107: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: don't kill URBs in interrupt context Serialization for the TX path was enforced by calling usb_kill_urb()/usb_kill_anchored_urbs(), to prevent transmission before a previous URB was completed. usb_tx_block() can be called from interrupt context (e.g. in the HCD giveback path), so we can't always use it to kill in-flight URBs. Prevent sleeping during interrupt context by checking the tx_submitted anchor for existing URBs. We now return -EBUSY, to indicate there's a pending request.
Affected products
- Linux Linux Kernel: from 5.10.252, before 5.11 (fixed in 5.11); from 5.15.202, before 5.16 (fixed in 5.16); from 6.1.165, before 6.2 (fixed in 6.2); from 6.6.128, before 6.7 (fixed in 6.7); from 6.12.75, before 6.13 (fixed in 6.13); from 6.18.16, before 6.18.33 (fixed in 6.18.33); …
Published 2026-06-24. Last modified 2026-07-23.