PT-2026-72192 · Linux · Linux Kernel

CVE-2026-72003

·

Published

2026-08-15

·

Updated

2026-08-18

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A remotely triggered heap overflow exists in the brcmfmac module. The brcmf notify auth frame rx() function calculates the frame length by subtracting the management header offset from the firmware event data length. Because the length check is insufficient, if the mgmt frame len is less than 24, the subtraction wraps as an unsigned value, resulting in an excessively large length during the memcpy() operation. This allows a malicious or malfunctioning Access Point (AP) to trigger the overflow during an external SAE auth exchange by sending a short authentication frame.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-72003

Affected Products

Linux Kernel