CVE-2025-37990
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/05/2025
Last modified:
21/05/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage()<br />
<br />
The function brcmf_usb_dl_writeimage() calls the function<br />
brcmf_usb_dl_cmd() but dose not check its return value. The<br />
&#39;state.state&#39; and the &#39;state.bytes&#39; are uninitialized if the<br />
function brcmf_usb_dl_cmd() fails. It is dangerous to use<br />
uninitialized variables in the conditions.<br />
<br />
Add error handling for brcmf_usb_dl_cmd() to jump to error<br />
handling path if the brcmf_usb_dl_cmd() fails and the<br />
&#39;state.state&#39; and the &#39;state.bytes&#39; are uninitialized.<br />
<br />
Improve the error message to report more detailed error<br />
information.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/08424a0922fb9e32a19b09d852ee87fb6c497538
- https://git.kernel.org/stable/c/508be7c001437bacad7b9a43f08a723887bcd1ea
- https://git.kernel.org/stable/c/524b70441baba453b193c418e3142bd31059cc1f
- https://git.kernel.org/stable/c/8e089e7b585d95122c8122d732d1d5ef8f879396
- https://git.kernel.org/stable/c/bdb435ef9815b1ae28eefffa01c6959d0fcf1fa7
- https://git.kernel.org/stable/c/fa9b9f02212574ee1867fbefb0a675362a71b31d