SB20260812349 - Double free in Linux kernel brcm80211 brcmfmac driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Double free (CVE-ID: CVE-2026-68192)
CWE-ID: CWE-415 - Double Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a double free in brcmf_pcie_release_scratchbuffers() when releasing scratch and ring update DMA buffers during reset and device removal. A local user can trigger repeated sequential release to cause a denial of service.
The issue occurs when reset teardown runs before device removal, causing the same DMA allocation to be freed a second time.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/044fca8f45ba9ab6ca526163155234cf88287ff5
- https://git.kernel.org/stable/c/0ca80328df23f851c86866720d4977783c919ee6
- https://git.kernel.org/stable/c/538c51e9d124cf656f2dd0c0394a8545efc7102d
- https://git.kernel.org/stable/c/5a045c2f0fbf029873d2295178fa0785ade35af0
- https://git.kernel.org/stable/c/b7d1d8cb1bdca56aecebacd2896615da0acc126a