Skip to main content
Vulnerability Database/CVE-2026-98350

CVE-2026-98350: Linux Kernel brcmfmac Information Disclosure

CVE-2026-98350 is an information disclosure vulnerability in the Linux kernel brcmfmac WiFi driver that causes stack data leakage to firmware. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-98350 Overview

CVE-2026-98350 is a Linux kernel vulnerability in the brcmfmac wireless driver, specifically in the Cypress (cyw) code path. The driver fails to zero out the auth_status structure during initialization. As a result, uninitialized stack data leaks from kernel memory to the WiFi firmware. The leak occurs when the SSID is shorter than 32 bytes or when params->pmkid is set. A secondary defect causes the driver to omit the Pairwise Master Key Identifier (PMKID) when passing authentication parameters to the firmware. This leads the firmware to cache a garbage PMKID after successful authentication and reject subsequent association requests that include the correct PMKID.

Critical Impact

Uninitialized kernel stack memory leaks to WiFi firmware, and connection reliability breaks when PMKID-based authentication is used.

Affected Products

  • Linux kernel versions containing the brcmfmac Cypress WiFi driver code path
  • Systems using Broadcom/Cypress WiFi chipsets handled by the cyw variant
  • Distributions shipping affected mainline and stable kernel releases prior to the fix commits

Discovery Timeline

  • 2026-10-06 - CVE-2026-98350 published to NVD
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-98350

Vulnerability Analysis

The defect resides in the brcmfmac driver's Cypress-specific authentication path. The driver constructs an auth_status structure on the stack and populates selected fields before passing the structure to the firmware. Because the structure is never zeroed on initialization, any field not explicitly written retains residual stack contents from prior function calls.

When the SSID occupies fewer than 32 bytes, the trailing bytes of the SSID buffer contain stale kernel stack data. The same leakage occurs when the caller supplies a params->pmkid value, because adjacent uninitialized bytes are copied along with the intended payload. The firmware then receives kernel memory contents it was never intended to see.

A parallel functional defect compounds the issue. The driver does not forward params->pmkid to the firmware when the value is present. The firmware consequently caches an incorrect PMKID derived from uninitialized memory on a successful authentication. Later association requests that include the legitimate PMKID are compared against the cached garbage value and denied.

Root Cause

The root cause is uninitialized memory use. The auth_status structure is allocated on the kernel stack without being cleared via memset or an equivalent initializer. This maps to the class of flaws tracked as uninitialized memory disclosure, closely related to [CWE-908] and [CWE-200].

Attack Vector

The attack vector is local to the kernel-firmware boundary within the affected system. An attacker does not need to send network traffic to trigger the leak; the condition is reached during normal authentication flows initiated by the host. The disclosed data travels from kernel stack into the WiFi firmware, where it may be observed by firmware debugging interfaces or persist in device memory accessible through subsequent requests. The functional PMKID defect additionally produces reliable connection failures that degrade availability for WPA2/WPA3 roaming scenarios that depend on PMKID caching.

See the vendor patches for implementation detail: Kernel Git Commit 6fba6233, Kernel Git Commit c2cf589c, and Kernel Git Commit e2de8d5e.

Detection Methods for CVE-2026-98350

Indicators of Compromise

  • Repeated WiFi association failures on systems using brcmfmac with Cypress chipsets after a successful authentication.
  • Kernel log entries from the brcmfmac subsystem referencing PMKID mismatches or authentication/association retries.
  • WiFi firmware crash dumps or diagnostic captures containing fragments that resemble kernel stack contents.

Detection Strategies

  • Inventory running kernel versions and correlate against the three fix commits to identify unpatched hosts.
  • Monitor dmesg and journald for brcmfmac warnings tied to authentication state transitions and PMKID handling.
  • Review firmware debug telemetry, when exposed by the chipset vendor, for unexpected binary content accompanying authentication frames.

Monitoring Recommendations

  • Centralize kernel and WiFi subsystem logs for continuous review across endpoint and IoT fleets.
  • Alert on anomalous wireless reassociation rates on devices using Broadcom/Cypress chipsets, which may indicate the PMKID caching defect.
  • Track kernel package versions through endpoint telemetry to confirm patch deployment coverage.

How to Mitigate CVE-2026-98350

Immediate Actions Required

  • Apply the upstream kernel patches referenced by commits 6fba6233, c2cf589c, and e2de8d5e as soon as distribution builds are available.
  • Prioritize patching on systems that use Broadcom/Cypress WiFi hardware with the brcmfmac driver, including laptops, embedded devices, and IoT gateways.
  • Reboot affected systems after updating the kernel package to activate the fixed driver.

Patch Information

The fix zeros auth_status on initialization and forwards params->pmkid to the firmware when it is present. The corrective changes are available in the stable kernel tree via Kernel Git Commit 6fba6233, Kernel Git Commit c2cf589c, and Kernel Git Commit e2de8d5e. Downstream distribution kernels should be upgraded to builds that include these commits.

Workarounds

  • Unload the brcmfmac module on systems that do not require Broadcom/Cypress WiFi connectivity until a patched kernel is installed.
  • Prefer wired network connectivity on affected hosts where feasible to avoid exercising the vulnerable authentication path.
  • Disable PMKID-based fast roaming configurations if they are observed to trigger association failures tied to the defect.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.