CVE-2026-90345 PUBLISHED

wifi: brcmfmac: fix P2P action frame handling without device vif

Assigner: Linux
Reserved: 11.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: brcmfmac: fix P2P action frame handling without device vif

Some P2P action frame paths assume the P2P device vif is always available. That is not true when userspace sends non-P2P public action frames through the primary interface, or when action-frame abort runs after the P2P device vif has not been created.

Fall back to the primary vif when aborting an action frame without a P2P device vif, and guard P2P device saved IE access before using it for peer channel search.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 6eda4e2c54255cd26a58d2fcec73ec3bff7a515b to f26e1b16904555e171292e183c3cfc1c38159fc5 (excl.)
  • affected from 6eda4e2c54255cd26a58d2fcec73ec3bff7a515b to 1b1edb9ebed49099bdc924cef49a9aea8b552199 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.9 is affected
  • unaffected from 0 to 3.9 (excl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References