PT-2026-72192 · Linux · Linux Kernel
CVE-2026-72003
·
Published
2026-08-15
·
Updated
2026-08-18
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A remotely triggered heap overflow exists in the
brcmfmac module. The brcmf notify auth frame rx() function calculates the frame length by subtracting the management header offset from the firmware event data length. Because the length check is insufficient, if the mgmt frame len is less than 24, the subtraction wraps as an unsigned value, resulting in an excessively large length during the memcpy() operation. This allows a malicious or malfunctioning Access Point (AP) to trigger the overflow during an external SAE auth exchange by sending a short authentication frame.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel