CVE-2023-53715

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/10/2025
Last modified:
22/10/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> wifi: brcmfmac: cfg80211: Pass the PMK in binary instead of hex<br /> <br /> Apparently the hex passphrase mechanism does not work on newer<br /> chips/firmware (e.g. BCM4387). It seems there was a simple way of<br /> passing it in binary all along, so use that and avoid the hexification.<br /> <br /> OpenBSD has been doing it like this from the beginning, so this should<br /> work on all chips.<br /> <br /> Also clear the structure before setting the PMK. This was leaking<br /> uninitialized stack contents to the device.

Impact