Junglewise Threat Intelligence

CVE-2024-58014: Linux Kernel brcmsmac out-of-bounds read in WiFi PHY component

CVE-2024-58014 · Severity: high · CVSS 7.1 · Published 2025-02-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Broadcom WiFi driver (brcmsmac). This flaw could allow a local user to trigger an out-of-bounds memory access, potentially leading to a system crash or unauthorized access to sensitive information stored in memory. The issue affects systems using specific Broadcom wireless hardware.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Linux kernel's brcmsmac WiFi driver. The function 'wlc_phy_iqcal_gainparams_nphy()' failed to validate the gain range index 'k' before using it to access the 'tbl_iqcal_gainparams_nphy' table. A local attacker with low privileges could potentially exploit this to read sensitive kernel memory or cause a denial of service (system crash). The fix introduces a range check using WARN_ON() to ensure the index does not exceed NPHY_IQCAL_NUMGAINS. Patches have been released for multiple stable kernel branches including 5.4, 5.10, 5.15, 6.1, 6.6, 6.12, and 6.13.

Affected products

  • Linux Linux Kernel 3.2 to 5.4.291, 5.5 to 5.10.235, 5.11 to 5.15.179, 5.16 to 6.1.129, 6.2 to 6.6.78, 6.7 to 6.12.14, 6.13 to 6.13.3

Timeline

  • 2024-12-10: other: Vulnerability identified and patch authored
  • 2025-02-26: advisory: NVD Published Date
  • 2025-02-27: disclosed: Public disclosure of the resolved vulnerability

References

Related threats