Impact
The vulnerability resides in the Linux kernel’s brcmfmac driver, where a short management frame received during an SAE authentication exchange can trigger a heap overflow. The driver incorrectly calculates the frame length, allowing an unsigned wrap that causes memory writes beyond the allocated buffer. An attacker can remotely supply such frames through a malicious or malfunctioning access point, potentially leading to arbitrary code execution on the device running the kernel.
Affected Systems
Systems running earlier versions of the Linux kernel that include the brcmfmac driver and the cyw component are affected. The fix is present in commits after the kernel revision referenced in the advisory, so any kernel version prior to that revision requires updating. The affected vendor is the Linux kernel maintainers.
Risk and Exploitability
The flaw permits remote exploitation via crafted Wi‑Fi frames, giving the attacker control over heap contents and potentially allowing execution of arbitrary code. No EPSS score is available, but the severity is high and the vulnerability is listed as not in the CISA KEV catalog. The attack vector is network‑based, requiring the device to receive a forged authentication frame, which is feasible for an attacker within wireless range.
OpenCVE Enrichment