Executive brief
A vulnerability was identified in the Linux kernel's Broadcom WiFi driver (brcmsmac). This flaw could allow a local user to trigger an out-of-bounds memory access, potentially leading to a system crash or unauthorized access to sensitive information stored in memory. The issue affects systems using specific Broadcom wireless hardware.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Linux kernel's brcmsmac WiFi driver. The function 'wlc_phy_iqcal_gainparams_nphy()' failed to validate the gain range index 'k' before using it to access the 'tbl_iqcal_gainparams_nphy' table. A local attacker with low privileges could potentially exploit this to read sensitive kernel memory or cause a denial of service (system crash). The fix introduces a range check using WARN_ON() to ensure the index does not exceed NPHY_IQCAL_NUMGAINS. Patches have been released for multiple stable kernel branches including 5.4, 5.10, 5.15, 6.1, 6.6, 6.12, and 6.13.
Affected products
- Linux Linux Kernel 3.2 to 5.4.291, 5.5 to 5.10.235, 5.11 to 5.15.179, 5.16 to 6.1.129, 6.2 to 6.6.78, 6.7 to 6.12.14, 6.13 to 6.13.3
Timeline
- 2024-12-10: other: Vulnerability identified and patch authored
- 2025-02-26: advisory: NVD Published Date
- 2025-02-27: disclosed: Public disclosure of the resolved vulnerability
References
- https://git.kernel.org/stable/c/093286c33409bf38896f2dab0c0bb6ca388afb33
- https://git.kernel.org/stable/c/0a457223cb2b9ca46bae7de387d0f4c093b0220d
- https://git.kernel.org/stable/c/13ef16c4fe384b1e70277bbe1d87934ee6c81e12
- https://git.kernel.org/stable/c/3f4a0948c3524ae50f166dbc6572a3296b014e62
- https://git.kernel.org/stable/c/6f6e293246dc1f5b2b6b3d0f2d757598489cda79
- https://git.kernel.org/stable/c/ada9df08b3ef683507e75b92f522fb659260147f
- https://git.kernel.org/stable/c/c27ce584d274f6ad3cba2294497de824a3c66646