Linux Kernel Vulnerability in brcmfmac WiFi Driver by Broadcom
CVE-2026-68403
What is CVE-2026-68403?
The brcmfmac WiFi driver in the Linux kernel contains a vulnerability related to the improper initialization of SDIO data work. During the probe process, the function brcmf_sdio_probe() attempts to allocate resources for the bus but may encounter a failure, leading to the unconditional call to brcmf_sdio_remove(). If this occurs before the data work item is properly initialized, it results in an attempt to cancel an invalid work object during cleanup. This flaw can be exploited to cause inconsistencies or crashes, potentially allowing further exploitation or denial of service.
Affected Version(s)
Linux 9982464379e81ece51ced03ebecbbcd34ea367a6
Linux 9982464379e81ece51ced03ebecbbcd34ea367a6 < 6bd21ec8549a5854dd64204a66289952917a924c
Linux 9982464379e81ece51ced03ebecbbcd34ea367a6 < 5c342437ea44bb829680ca9e4f683dd5b325b219