Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: brcmfmac: cyw: fix heap overflow on a short auth frame

brcmf_notify_auth_frame_rx() takes the frame length from the firmware
event and copies the frame body with the management header offset
subtracted:

u32 mgmt_frame_len = e->datalen - sizeof(struct brcmf_rx_mgmt_data);
...
memcpy(&mgmt_frame->u, frame,
mgmt_frame_len - offsetof(struct ieee80211_mgmt, u));

The only length check is e->datalen >= sizeof(*rxframe), so mgmt_frame_len
can be anything from 0 up. offsetof(struct ieee80211_mgmt, u) is 24. When
mgmt_frame_len is below that, the subtraction wraps as an unsigned value to
a huge length. The memcpy then runs far past the kzalloc'd buffer. A
malicious or malfunctioning AP can make the frame short during the
external SAE auth exchange, so this is a remotely triggered heap overflow.

Reject frames shorter than the management header offset before the copy.
Published: 2026-08-15
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Linux kernel’s brcmfmac driver, where a short management frame received during an SAE authentication exchange can trigger a heap overflow. The driver incorrectly calculates the frame length, allowing an unsigned wrap that causes memory writes beyond the allocated buffer. An attacker can remotely supply such frames through a malicious or malfunctioning access point, potentially leading to arbitrary code execution on the device running the kernel.

Affected Systems

Systems running earlier versions of the Linux kernel that include the brcmfmac driver and the cyw component are affected. The fix is present in commits after the kernel revision referenced in the advisory, so any kernel version prior to that revision requires updating. The affected vendor is the Linux kernel maintainers.

Risk and Exploitability

The flaw permits remote exploitation via crafted Wi‑Fi frames, giving the attacker control over heap contents and potentially allowing execution of arbitrary code. No EPSS score is available, but the severity is high and the vulnerability is listed as not in the CISA KEV catalog. The attack vector is network‑based, requiring the device to receive a forged authentication frame, which is feasible for an attacker within wireless range.

Generated by OpenCVE AI on August 15, 2026 at 07:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a kernel update that includes commit 185bb156c427d0f865d344a6d0eaa02c6d05cc57 or later to address the heap overflow in brcmfmac
  • If an immediate kernel upgrade is not possible, disable the brcmfmac wireless driver or de‑activate Wi‑Fi functionality to block the exploit surface
  • Continuously monitor network traffic for anomalous short authentication frames and enforce stricter AP authentication policies in the environment

Generated by OpenCVE AI on August 15, 2026 at 07:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cyw: fix heap overflow on a short auth frame brcmf_notify_auth_frame_rx() takes the frame length from the firmware event and copies the frame body with the management header offset subtracted: u32 mgmt_frame_len = e->datalen - sizeof(struct brcmf_rx_mgmt_data); ... memcpy(&mgmt_frame->u, frame, mgmt_frame_len - offsetof(struct ieee80211_mgmt, u)); The only length check is e->datalen >= sizeof(*rxframe), so mgmt_frame_len can be anything from 0 up. offsetof(struct ieee80211_mgmt, u) is 24. When mgmt_frame_len is below that, the subtraction wraps as an unsigned value to a huge length. The memcpy then runs far past the kzalloc'd buffer. A malicious or malfunctioning AP can make the frame short during the external SAE auth exchange, so this is a remotely triggered heap overflow. Reject frames shorter than the management header offset before the copy.
Title wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-15T05:51:34.730Z

Reserved: 2026-08-09T03:40:39.898Z

Link: CVE-2026-72003

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:20:53.557

Modified: 2026-08-15T06:20:53.557

Link: CVE-2026-72003

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T08:30:05Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')