HIGH Introduced in 6.16
brcmfmac AuthFrame Overflow
CVE-2026-72003
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI8.7HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cyw: fix heap overflow on a short auth frame brcmf_notify_auth_frame_rx() takes the frame length from the firmware event and copies the frame body with the management header offset subtracted: u32 mgmt_frame_len = e->datalen - sizeof(struct brcmf_rx_mgmt_data); ... memcpy(&mgmt_frame->u, frame, mgmt_frame_len - offsetof(struct ieee80211_mgmt, u)); The only length check is e->datalen >= sizeof(*rxframe), so mgmt_frame_len can be anything from 0 up. offsetof(struct ieee80211_mgmt, u) is 24. When mgmt_frame_len is below that, the subtraction wraps as an unsigned value to a huge length. The memcpy then runs far past the kzalloc'd buffer. A malicious or malfunctioning AP can make the frame short during the external SAE auth exchange, so this is a remotely triggered heap overflow. Reject frames shorter than the management header offset before the copy.
02KernelScan AI Analysis
Risk summary
A nearby malicious WiFi access point can trigger a heap buffer overflow in the brcmfmac CYW driver by sending a short authentication frame during the SAE authentication exchange. The overflow corrupts kernel heap memory and can lead to arbitrary code execution or a kernel crash on the affected device.
Vulnerability analysis
When the brcmfmac CYW WiFi driver receives an authentication frame from firmware, it computes the frame body length by subtracting a fixed header size from the total event data length. The only existing length check ensures the event is large enough to contain the firmware header, but does not verify the remaining frame body is large enough for the IEEE 802.11 management header. When a frame body is shorter than that header, an unsigned integer subtraction wraps to a huge value, and the subsequent memory copy writes far past a heap-allocated buffer. A nearby malicious or malfunctioning access point can trigger this during the external SAE authentication exchange by sending a deliberately short frame, requiring no prior authentication or user interaction. The fix rejects any frame whose body is shorter than the management header offset before the copy is performed.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| mainline | 6.16 | 7.2-rc4 | 240c8d2c717b |
| 6.18 | 6.16 | 6.18.40 | 55b26abb1fa1 |
| 7.1 | 6.16 | 7.1.5 | 185bb156c427 |