Impact
The brcmfmac wireless driver in the Linux kernel had a memory leak in the brcmf_sdio_read_control() function because the allocated buffer was not freed in certain error paths. Each time the error path is triggered, kernel memory grows, eventually exhausting available RAM, degrading system performance and potentially causing a kernel panic or crash. The flaw is a resource exhaustion flaw identified as CWE‑772.
Affected Systems
All Linux kernel releases that include the Broadcom brcmfmac wireless driver and the unmodified brcmf_sdio_read_control() code are affected. No specific version list is available, but any kernel build that contains the missing vfree() calls in this function is vulnerable.
Risk and Exploitability
The CVSS score is 5.3 (moderate severity) and the EPSS score is below 1%, indicating a low likelihood of widespread exploitation. The CVE is not listed in the CISA KEV catalog. The vulnerability could be triggered by a local or privileged user who initiates conditions that exercise the problematic error paths in brcmf_sdio_read_control(). Based on the description, it is inferred that such an attacker could send crafted SDIO commands. Because the leak occurs in kernel space, remote exploitation without additional vulnerabilities would be unlikely.
OpenCVE Enrichment
Debian DSA