Linux Kernel Wi-Fi Brcmfmac Component Bsscfg Index Validation Vulnerability

Vulnerability

A vulnerability exists in the Linux kernel's handling of interface events for the Brcmfmac Wi-Fi driver. The issue arises because the driver validates the firmware-provided interface index but fails to properly check the corresponding Bsscfg index before using it to access the driver's interface list. This oversight could lead to invalid memory access or other unintended behavior.

Impact

Improper validation of Bsscfg indices in the Brcmfmac Wi-Fi driver can result in memory corruption or undefined behavior, potentially leading to a denial of service or other security issues.

Reproduction

The vulnerability can be reproduced by sending interface events to the Brcmfmac driver with invalid Bsscfg indices that do not correspond to the driver's interface list. This can be done by manipulating the firmware or using a custom driver that sends such events.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. The specific commit that resolves this issue is available in the Linux kernel stable tree.

Added: May 6, 2026, 10:36 AM
Updated: May 6, 2026, 10:36 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.3
remediation
7.7
relevance
7.6
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.