Description
In the Linux kernel, the following vulnerability has been resolved:

wifi: brcmfmac: fix P2P action frame handling without device vif

Some P2P action frame paths assume the P2P device vif is always
available. That is not true when userspace sends non-P2P public action
frames through the primary interface, or when action-frame abort runs
after the P2P device vif has not been created.

Fall back to the primary vif when aborting an action frame without a P2P
device vif, and guard P2P device saved IE access before using it for
peer channel search.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash
Action: Patch immediately
AI Analysis

Impact

The flaw in the brcmfmac driver caused paths that handle P2P action frames to assume a P2P device virtual interface (vif) was always present. When userspace sent non‑P2P public action frames on the primary interface or when an abort operation ran after the P2P device had not been created, the driver attempted to access data that did not exist. This could lead to an invalid memory access, potentially crashing the kernel and resulting in a denial‑of‑service condition on the affected system.

Affected Systems

The vulnerability exists in the Linux kernel’s brcmfmac wireless driver, as distributed by the Linux community. No specific kernel version is listed, so any kernel build that includes the brcmfmac driver – particularly those compiled for Broadcom wireless chips – could be affected.

Risk and Exploitability

The EPSS score of less than 1 % indicates that the likelihood of exploitation in the wild is currently low, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw can trigger a kernel crash, the potential impact is high if an attacker can deliver crafted P2P action frames. The attack vector is likely local or remote through the wireless interface, depending on network exposure and whether the compromised machine can receive wireless traffic from an external source.

Generated by OpenCVE AI on September 19, 2026 at 04:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that incorporates the brcmfmac patch or apply the specific commit that fixes P2P action frame handling
  • Rebuild or install the latest brcmfmac firmware that includes the updated driver code
  • If an immediate kernel upgrade is not possible, disable P2P functionality or block action frame transmission on the wireless interface to prevent the fault from being triggered

Generated by OpenCVE AI on September 19, 2026 at 04:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix P2P action frame handling without device vif Some P2P action frame paths assume the P2P device vif is always available. That is not true when userspace sends non-P2P public action frames through the primary interface, or when action-frame abort runs after the P2P device vif has not been created. Fall back to the primary vif when aborting an action frame without a P2P device vif, and guard P2P device saved IE access before using it for peer channel search.
Title wifi: brcmfmac: fix P2P action frame handling without device vif
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:54.958Z

Reserved: 2026-09-11T19:38:34.805Z

Link: CVE-2026-90345

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:33.230

Modified: 2026-09-17T17:17:33.230

Link: CVE-2026-90345

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T05:30:17Z

Weaknesses