CVE-2026-31661
Description
A flaw was found in the Linux kernel's brcmsmac Wi-Fi driver. This vulnerability arises from an incorrect size used during memory deallocation (dma_free_coherent) that does not match the size allocated (dma_alloc_consistent), which may be adjusted for alignment. An attacker could potentially exploit this memory mismatch, leading to memory corruption. This could result in a denial of service or other unpredictable system behavior.
Statement
A Moderate impact flaw was found in the Linux kernel's brcmsmac Wi-Fi driver. This memory corruption vulnerability occurs due to an incorrect size being used during memory deallocation, which does not match the original allocation size. Exploitation could lead to a denial of service or other system instability on systems utilizing affected Broadcom wireless hardware.
Mitigation
To mitigate this issue, prevent the `brcmsmac` kernel module from loading if it is not required for your system's operation. This can be achieved by blacklisting the module.
To blacklist the `brcmsmac` module:
1. Create a new file `/etc/modprobe.d/blacklist-brcmsmac.conf` with the following content:
blacklist brcmsmac2. Regenerate the initramfs to ensure the blacklist is applied during boot:
For RHEL 7:
bashFor RHEL 8 and 9:
dracut -f -v
bash3. Reboot the system for the changes to take effect.
dracut -f --regenerate-all
This mitigation may impact systems relying on Broadcom wireless hardware that uses the `brcmsmac` driver, as wireless functionality will be disabled. A system reboot is required for the changes to be applied.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 5.5 | 5.5 | N/A |
| Attack Vector | Local | Local | N/A |
| Attack Complexity | Low | Low | N/A |
| Privileges Required | Low | Low | N/A |
| User Interaction | None | None | N/A |
| Scope | Unchanged | Unchanged | N/A |
| Confidentiality | None | None | N/A |
| Integrity Impact | None | None | N/A |
| Availability Impact | High | High | N/A |
Vector
Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Integrity,Availability,Confidentiality
Technical Impact: Modify Memory; DoS: Crash, Exit, or Restart; Execute Unauthorized Code or Commands
This weakness may result in the corruption of memory, and perhaps instructions, possibly leading to a crash. If the corrupted memory can be effectively controlled, it may be possible to execute arbitrary code.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.