Impact
During WPA authentication in 802.1X SHA-256 mode on Linux systems that use the Broadcom brcmfmac driver, a missing configuration for use_fwsup triggers a call‑trace warning when the kernel attempts to call brcmf_cfg80211_set_pmk(). The warning is a DEBUG/TRACE output and does not expose any confidentiality, integrity, or availability flaw; it merely indicates a configuration or coding issue that could lead to noisy logs but not to exploitation.
Affected Systems
Any Linux kernel host that loads the brcmfmac wireless driver for Broadcom Wi‑Fi hardware is potentially affected. The issue appears in kernel variants that have the unpatched brcmfmac firmware stack and are using 802.1X with SHA-256 authentication.
Risk and Exploitability
No evidence exists that this condition allows an attacker to execute code, bypass authentication, or disrupt network operations. The CVSS score is 5.3, EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. At most, the behavior indicates a misconfiguration that could obscure legitimate error messages.
OpenCVE Enrichment
Debian DLA