cbcvebase.
CVE-2025-71154
published 2026-01-23

CVE-2025-71154: In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix memory leak on usb_submit_urb() failure In async_set_registers()…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.7th percentile
In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix memory leak on usb_submit_urb() failure In async_set_registers(), when usb_submit_urb() fails, the allocated async_req structure and URB are not freed, causing a memory leak. The completion callback async_set_reg_cb() is responsible for freeing these allocations, but it is only called after the URB is successfully submitted and completes (successfully or with error). If submission fails, the callback never runs and the memory is leaked. Fix this by freeing both the URB and the request structure in the error path when usb_submit_urb() fails.

Affected

53 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 4d12997a9bb3d217ad4b925ec3074ec89364bf95 < a4e2442d3c48355a84463342f397134f149936d7a4e2442d3c48355a84463342f397134f149936d7
linuxlinux>= 4d12997a9bb3d217ad4b925ec3074ec89364bf95 < 2f966186b99550e3c665dbfb87b8314e30acea022f966186b99550e3c665dbfb87b8314e30acea02
linuxlinux>= 4d12997a9bb3d217ad4b925ec3074ec89364bf95 < db2244c580540306d60ce783ed340190720cd429db2244c580540306d60ce783ed340190720cd429
linuxlinux>= 4d12997a9bb3d217ad4b925ec3074ec89364bf95 < 4bd4ea3eb326608ffc296db12c105f92dc2f21904bd4ea3eb326608ffc296db12c105f92dc2f2190
linuxlinux>= 4d12997a9bb3d217ad4b925ec3074ec89364bf95 < 6492ad6439ff1a479fc94dc6052df3628faed8b66492ad6439ff1a479fc94dc6052df3628faed8b6
linuxlinux>= 4d12997a9bb3d217ad4b925ec3074ec89364bf95 < 151403e903840c9cf06754097b6732c14f26c532151403e903840c9cf06754097b6732c14f26c532
linuxlinux>= 4d12997a9bb3d217ad4b925ec3074ec89364bf95 < 12cab1191d9890097171156d06bfa8d31f1e39c812cab1191d9890097171156d06bfa8d31f1e39c8
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.5-16.18.5-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 3.10.1 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13 < 6.18.46.18.4
linuxlinux_kernel>= 6.2 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7 < 6.12.646.12.64
ubuntulinux-aws
ubuntulinux-aws-6.17

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.