In the Linux kernel, the following vulnerability has been resolved:
staging: rtl8723bs: fix a potential memory leak in rtw_init_cmd_priv()
In rtw_init_cmd_priv(), if `pcmdpriv->rsp_allocated_buf` is allocated in failure, then `pcmdpriv->cmd_allocated_buf` will be not properly released. Besides, considering there are only two error paths and the first one can directly return, so we do not need implicitly jump to the `exit` tag to execute the error handler.
So this patch added `kfree(pcmdpriv->cmd_allocated_buf);` on the error path to release the resource and simplified the return logic of rtw_init_cmd_priv(). As there is no proper device to test with, no runtime testing was performed.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Oct 9, 2025 | Oct 9, 2025 |
| Ubuntu | — | Upgrade linux-intel-iotgUpgrade linuxUpgrade linux-aws-fipsUpgrade linux-aws-5.4Upgrade linux-gkeUpgrade linux-azure-fipsUpgrade linux-gcp-fipsUpgrade linux-ibmUpgrade linux-azure-5.15Upgrade linux-fipsUpgrade linux-oracleUpgrade linux-ibm-5.4Upgrade linux-nvidiaUpgrade linux-gkeopUpgrade linux-lowlatencyUpgrade linux-xilinx-zynqmpUpgrade linux-oracle-5.15Upgrade linux-riscv-5.15Upgrade linux-azure-fde-5.15Upgrade linux-gcp-5.4Upgrade linux-intel-iotg-5.15Upgrade linux-kvmUpgrade linux-azure-5.4Upgrade linux-hwe-5.4Upgrade linux-awsUpgrade linux-iotUpgrade linux-oracle-5.4Upgrade linux-realtimeUpgrade linux-raspi-5.4Upgrade linux-azureUpgrade linux-azure-fdeUpgrade linux-hwe-5.15Upgrade linux-raspiUpgrade linux-gcp-5.15Upgrade linux-gcpUpgrade linux-lowlatency-hwe-5.15Upgrade linux-bluefieldUpgrade linux-aws-5.15 | Oct 10, 2025 | Oct 7, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Oct 15, 2025 | Oct 7, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub