Impact
An issue within the Linux kernel’s brcmfmac SDIO driver allows device removal code to cancel an uninitialized work queue item. This misordering can trigger a crash during driver probe failure or removal, potentially causing a system-wide failure or offering a local attack surface for denial of service.
Affected Systems
The vulnerability affects all Linux kernel builds that include the brcmfmac SDIO driver, regardless of specific kernel version. It is a kernel‑level fault and would manifest on machines that load this driver for wireless SDIO devices.
Risk and Exploitability
The CVSS score is not provided, and the EPSS entry is unavailable, making precise quantification difficult. The vulnerability is not included in the CISA KEV catalog, suggesting no widespread exploitation reported. Nonetheless, because the flaw only triggers on driver probe or removal pathways, it is likely exploitable locally by an attacker able to reboot the device, insert a faulty SDIO peripheral, or otherwise force the probe failure. The high impact of a kernel crash warrants a cautious stance. The attack vector appears to involve device-level interaction; due to the lack of external attack evidence, the risk primarily concerns local or privileged users.
OpenCVE Enrichment