CVE-2026-68410: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix memory leak in helper_firmware_cb() helper_firmware_cb() neglects to free the single-stage firmware image after a successful async load, leading to a memory leak in the USB firmware-download path. Fix this memory leak by calling release_firmware() immediately after lbs_fw_loaded() returns. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in the current wireless tree. An x86_64 allyesconfig build showed no new warnings. As we do not have compatible Libertas USB hardware for exercising this firmware-download path, no runtime testing was able to be performed.

Affected products

  • Linux Linux: from 3.13, before 5.10.265 (fixed in 5.10.265); from 5.11, before 5.15.216 (fixed in 5.15.216); from 5.16, before 6.1.183 (fixed in 6.1.183); from 6.2, before 6.6.148 (fixed in 6.6.148); from 6.7, before 6.12.101 (fixed in 6.12.101); from 6.13, before 6.18.42 (fixed in 6.18.42); …

Published 2026-08-10. Last modified 2026-08-19.