{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-68192","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-30T09:28:09.373Z","datePublished":"2026-08-10T12:00:10.041Z","dateUpdated":"2026-08-19T16:31:06.873Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-19T16:31:06.873Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: make release_scratchbuffers idempotent\n\nbrcmf_pcie_release_scratchbuffers() frees the shared.scratch and\nshared.ringupd DMA buffers with dma_free_coherent() but does not clear\nthe pointers afterwards, unlike the sibling release_ringbuffers() which\nNULLs commonrings/flowrings/idxbuf on release.\n\nBoth the bus_reset .reset callback (brcmf_pcie_reset) and\nbrcmf_pcie_remove() call release_scratchbuffers.  When reset teardown\nhas run before removal, remove's own teardown would call\ndma_free_coherent() a second time on the already-freed DMA allocation.\n\nNULL the pointers after free, matching release_ringbuffers(), so a later\nrelease observes that the allocation has already been released.  This\npatch makes repeated sequential release safe; the reset-work lifetime is\nhandled separately by the following patch.\n\nThis issue was found by an in-house static analysis tool."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The flaw is reached during brcmfmac PCIe bus reset/teardown after firmware halt; brcmf_fw_crashed() is invoked from the threaded IRQ handler on BRCMF_D2H_DEV_FWHALT mailbox data from the WiFi firmware, which an adjacent attacker can trigger with crafted over-the-air WiFi traffic to crash the dongle.\nAC:L - An attacker who induces firmware halt controls the reset sequence; brcmf_pcie_reset() always frees scratch buffers first and a later brcmf_pcie_remove() or failed brcmf_pcie_setup() teardown calls release_scratchbuffers() again on the same stale pointers, making the double-free deterministic without races they cannot influence.\nPR:N - No host privileges are required because crashing Broadcom FullMAC firmware via adjacent WiFi frames reaches brcmf_fw_crashed() without authentication, CAP_NET_ADMIN, or local access; the debugfs reset path is root-only but is not needed for the highest-impact attack scenario.\nUI:N - Exploitation only requires a victim with an active brcmfmac PCIe WiFi interface within RF range; no victim click, file open, driver unload, or other explicit user action is needed beyond normal always-on WiFi operation on laptops and embedded hosts using Broadcom PCIe FullMAC chips.\nS:U - The vulnerability corrupts kernel DMA/page-allocator state and enables host kernel privilege escalation within the same security authority; it does not cross VM, container, or IOMMU boundaries, so scope remains unchanged.\nC:H - Calling dma_free_coherent() twice on the same scratch and ringupd DMA allocations is a double-free of kernel coherent memory; this allocator-metadata corruption can be leveraged for arbitrary kernel memory disclosure even when full exploitation is not attempted, per kernel CVSS guidance for memory corruption.\nI:H - Double-free of dma_alloc_coherent buffers corrupts the kernel DMA/page heap freelist, enabling attacker-controlled reallocation and arbitrary kernel writes or control-flow hijack on systems with BRCMFMAC_PCIE enabled and a reachable Broadcom PCIe FullMAC wireless device.\nA:H - Re-freeing already released DMA-coherent allocations during driver reset or removal typically causes immediate kernel BUG/oops/panic or fatal allocator corruption during teardown, guaranteeing severe host availability loss on affected Broadcom PCIe WiFi systems even when code execution is not achieved."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c"],"versions":[{"version":"4684997d9eea29380000e062755aa6d368d789a3","lessThan":"81c58a206d1deee01f4c29236d4154c0872f2a38","status":"affected","versionType":"git"},{"version":"4684997d9eea29380000e062755aa6d368d789a3","lessThan":"382ee00b2d1e31869ae576a60d3fbe7a2153512f","status":"affected","versionType":"git"},{"version":"4684997d9eea29380000e062755aa6d368d789a3","lessThan":"739b686aecdb14a6065300ea53401f043e51fd22","status":"affected","versionType":"git"},{"version":"4684997d9eea29380000e062755aa6d368d789a3","lessThan":"b7d1d8cb1bdca56aecebacd2896615da0acc126a","status":"affected","versionType":"git"},{"version":"4684997d9eea29380000e062755aa6d368d789a3","lessThan":"5a045c2f0fbf029873d2295178fa0785ade35af0","status":"affected","versionType":"git"},{"version":"4684997d9eea29380000e062755aa6d368d789a3","lessThan":"044fca8f45ba9ab6ca526163155234cf88287ff5","status":"affected","versionType":"git"},{"version":"4684997d9eea29380000e062755aa6d368d789a3","lessThan":"0ca80328df23f851c86866720d4977783c919ee6","status":"affected","versionType":"git"},{"version":"4684997d9eea29380000e062755aa6d368d789a3","lessThan":"538c51e9d124cf656f2dd0c0394a8545efc7102d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c"],"versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","status":"unaffected","versionType":"semver"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.6.148"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.12.101"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.18.42"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"7.1.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/81c58a206d1deee01f4c29236d4154c0872f2a38"},{"url":"https://git.kernel.org/stable/c/382ee00b2d1e31869ae576a60d3fbe7a2153512f"},{"url":"https://git.kernel.org/stable/c/739b686aecdb14a6065300ea53401f043e51fd22"},{"url":"https://git.kernel.org/stable/c/b7d1d8cb1bdca56aecebacd2896615da0acc126a"},{"url":"https://git.kernel.org/stable/c/5a045c2f0fbf029873d2295178fa0785ade35af0"},{"url":"https://git.kernel.org/stable/c/044fca8f45ba9ab6ca526163155234cf88287ff5"},{"url":"https://git.kernel.org/stable/c/0ca80328df23f851c86866720d4977783c919ee6"},{"url":"https://git.kernel.org/stable/c/538c51e9d124cf656f2dd0c0394a8545efc7102d"}],"title":"wifi: brcmfmac: make release_scratchbuffers idempotent","x_generator":{"engine":"bippy-1.2.0"}}}}