Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: brcmfmac: cyw: fix heap overflow on a short auth frame

brcmf_notify_auth_frame_rx() takes the frame length from the firmware
event and copies the frame body with the management header offset
subtracted:

u32 mgmt_frame_len = e->datalen - sizeof(struct brcmf_rx_mgmt_data);
...
memcpy(&mgmt_frame->u, frame,
mgmt_frame_len - offsetof(struct ieee80211_mgmt, u));

The only length check is e->datalen >= sizeof(*rxframe), so mgmt_frame_len
can be anything from 0 up. offsetof(struct ieee80211_mgmt, u) is 24. When
mgmt_frame_len is below that, the subtraction wraps as an unsigned value to
a huge length. The memcpy then runs far past the kzalloc'd buffer. A
malicious or malfunctioning AP can make the frame short during the
external SAE auth exchange, so this is a remotely triggered heap overflow.

Reject frames shorter than the management header offset before the copy.
Published: 2026-08-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Linux kernel’s brcmfmac wireless driver allows a crafted Wi‑Fi authentication frame to trigger a heap overflow. During the SAE authentication exchange, the driver computes the frame length from data received from the firmware and performs a memcpy without properly bounding the length, resulting in a wraparound when the frame is shorter than the management header. The overflow can overwrite kernel heap memory, giving an attacker the potential to execute arbitrary code on the device. The flaw is consequent of a lack of bounds checking and the unsigned wraparound behavior in the length calculation.

Affected Systems

All systems that run a Linux kernel with the brcmfmac driver and the cyw component are potentially impacted. The issue exists in any kernel version prior to the commit that implements the overflow guard, as referenced in the advisory. The fix is present in kernels that have incorporated commit 185bb156c427d0f865d344a6d0eaa02c6d05cc57 or later. Consequently, any distribution that includes these older kernel versions and uses the brcmfmac driver is at risk.

Risk and Exploitability

The vulnerability can be leveraged remotely over a wireless connection; the analysis infers that an attacker who can send forged authentication frames to a target device—such as by operating a malicious or malfunctioning access point—can exploit this flaw. The CVSS score of 8.8 indicates a high severity impact, while the EPSS score of <1% suggests the probability of exploitation is currently low but not zero. The flaw is not listed in the CISA KEV catalog, and no public exploits have been reported, but the nature of the vulnerability allows an attacker to potentially take control of the kernel if successful.

Generated by OpenCVE AI on August 18, 2026 at 06:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a kernel update that includes commit 185bb156c427d0f865d344a6d0eaa02c6d05cc57 or later to address the heap overflow in brcmfmac
  • If an immediate kernel upgrade is not possible, disable the brcmfmac wireless driver or de‑activate Wi‑Fi functionality to block the exploit surface
  • Continuously monitor network traffic for anomalous short authentication frames and enforce stricter AP authentication policies in the environment

Generated by OpenCVE AI on August 18, 2026 at 06:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-805
References
Metrics threat_severity

None

threat_severity

Important


Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cyw: fix heap overflow on a short auth frame brcmf_notify_auth_frame_rx() takes the frame length from the firmware event and copies the frame body with the management header offset subtracted: u32 mgmt_frame_len = e->datalen - sizeof(struct brcmf_rx_mgmt_data); ... memcpy(&mgmt_frame->u, frame, mgmt_frame_len - offsetof(struct ieee80211_mgmt, u)); The only length check is e->datalen >= sizeof(*rxframe), so mgmt_frame_len can be anything from 0 up. offsetof(struct ieee80211_mgmt, u) is 24. When mgmt_frame_len is below that, the subtraction wraps as an unsigned value to a huge length. The memcpy then runs far past the kzalloc'd buffer. A malicious or malfunctioning AP can make the frame short during the external SAE auth exchange, so this is a remotely triggered heap overflow. Reject frames shorter than the management header offset before the copy.
Title wifi: brcmfmac: cyw: fix heap overflow on a short auth frame
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:39:21.650Z

Reserved: 2026-08-09T03:40:39.898Z

Link: CVE-2026-72003

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:20:53.557

Modified: 2026-08-17T06:17:57.717

Link: CVE-2026-72003

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72003 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T06:30:08Z

Weaknesses
  • CWE-805

    Buffer Access with Incorrect Length Value