Executive brief
A vulnerability was identified in the Linux kernel's Broadcom Wi-Fi driver (brcmfmac) that could allow a local attacker to cause a system crash or potentially execute unauthorized code. The issue occurs during the shutdown process of the Wi-Fi and Bluetooth coexistence component, where a timing conflict can lead to the system attempting to use memory that has already been cleared. This could impact system stability and the security of data handled by the wireless driver.
Technical details
A use-after-free vulnerability exists in the brcmfmac Wi-Fi driver within the brcmf_btcoex_detach() function. The root cause is a race condition where the btcoex timer handler (brcmf_btcoex_timerfunc) sets a 'timer_on' flag to false, causing the detachment routine to skip timer_shutdown_sync(). This allows the timer to potentially reschedule worker threads after the underlying brcmf_btcoex_info structure has been freed. An attacker with local access could exploit this race condition to trigger a use-after-free, leading to kernel memory corruption or a denial-of-service (system crash). The fix involves removing the conditional check and calling timer_shutdown_sync() unconditionally to ensure the timer is deactivated before memory is freed.
Affected products
- Linux Linux Kernel 3.10 to 6.1.167, 6.6.x, 6.10.x, 6.11.x
Timeline
- 2025-08-22: disclosed: Initial patch submitted by Duoming Zhou
- 2025-09-09: patched: Patch committed to stable branches
- 2025-09-19: advisory: CVE-2025-39863 published in NVD
References
- https://git.kernel.org/stable/c/2f6fbc8e04ca1d1d5c560be694199f847229c625
- https://git.kernel.org/stable/c/3e789f8475f6c857c88de5c5bf4b24b11a477dd7
- https://git.kernel.org/stable/c/9cb83d4be0b9b697eae93d321e0da999f9cdfcfc
- https://git.kernel.org/stable/c/ae58f70bde0433f27ef4b388ab50634736607bf6
- https://git.kernel.org/stable/c/c75600e69e66a751cc046cd9c407b942f298d852
- https://git.kernel.org/stable/c/f1150153c4e5940fe49ab51136343c5b4fe49d63