Impact
The flaw in the brcmfmac driver caused paths that handle P2P action frames to assume a P2P device virtual interface (vif) was always present. When userspace sent non‑P2P public action frames on the primary interface or when an abort operation ran after the P2P device had not been created, the driver attempted to access data that did not exist. This could lead to an invalid memory access, potentially crashing the kernel and resulting in a denial‑of‑service condition on the affected system.
Affected Systems
The vulnerability exists in the Linux kernel’s brcmfmac wireless driver, as distributed by the Linux community. No specific kernel version is listed, so any kernel build that includes the brcmfmac driver – particularly those compiled for Broadcom wireless chips – could be affected.
Risk and Exploitability
The EPSS score of less than 1 % indicates that the likelihood of exploitation in the wild is currently low, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw can trigger a kernel crash, the potential impact is high if an attacker can deliver crafted P2P action frames. The attack vector is likely local or remote through the wireless interface, depending on network exposure and whether the compromised machine can receive wireless traffic from an external source.
OpenCVE Enrichment