What is CVE-2026-72003?
A heap overflow vulnerability (CVE-2026-72003) was resolved in the Linux kernel's brcmfmac driver for Broadcom FullMAC Wi-Fi adapters. The issue occurs in `brcmf_notify_auth_frame_rx()` when processing short auth frames, as the firmware-reported frame length is used without proper validation, potentially leading to a buffer overflow. Apply the security patch or update to the fixed kernel version immediately.
Azərbaycanca: Linux kernel-in brcmfmac sürücüsündə CVE-2026-72003 heap overflow zəifliyi aşkarlanıb. Qısa autentifikasiya çərçivəsi qəbul edildikdə `brcmf_notify_auth_frame_rx()` funksiyasında firmware-dən gələn uzunluq düzgün yoxlanılmadığı üçün bufer daşması baş verə bilər. Təhlükəsizlik yaması tətbiq edilməli və ya təsirlənmiş Broadcom FullMAC Wi-Fi adapterləri üçün kernel yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Linux
FAQ2
In which component of the Linux kernel does the CVE-2026-72003 vulnerability exist?
The CVE-2026-72003 vulnerability exists in the brcmfmac driver for Broadcom FullMAC Wi-Fi adapters in the Linux kernel.
Under what conditions does the CVE-2026-72003 heap overflow vulnerability occur?
The vulnerability occurs in the `brcmf_notify_auth_frame_rx()` function when processing short auth frames, as the firmware-reported frame length is used without proper validation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.