CVE-2026-68192
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2026
Last modified:
19/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
wifi: brcmfmac: make release_scratchbuffers idempotent<br />
<br />
brcmf_pcie_release_scratchbuffers() frees the shared.scratch and<br />
shared.ringupd DMA buffers with dma_free_coherent() but does not clear<br />
the pointers afterwards, unlike the sibling release_ringbuffers() which<br />
NULLs commonrings/flowrings/idxbuf on release.<br />
<br />
Both the bus_reset .reset callback (brcmf_pcie_reset) and<br />
brcmf_pcie_remove() call release_scratchbuffers. When reset teardown<br />
has run before removal, remove&#39;s own teardown would call<br />
dma_free_coherent() a second time on the already-freed DMA allocation.<br />
<br />
NULL the pointers after free, matching release_ringbuffers(), so a later<br />
release observes that the allocation has already been released. This<br />
patch makes repeated sequential release safe; the reset-work lifetime is<br />
handled separately by the following patch.<br />
<br />
This issue was found by an in-house static analysis tool.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/044fca8f45ba9ab6ca526163155234cf88287ff5
- https://git.kernel.org/stable/c/0ca80328df23f851c86866720d4977783c919ee6
- https://git.kernel.org/stable/c/382ee00b2d1e31869ae576a60d3fbe7a2153512f
- https://git.kernel.org/stable/c/538c51e9d124cf656f2dd0c0394a8545efc7102d
- https://git.kernel.org/stable/c/5a045c2f0fbf029873d2295178fa0785ade35af0
- https://git.kernel.org/stable/c/739b686aecdb14a6065300ea53401f043e51fd22
- https://git.kernel.org/stable/c/81c58a206d1deee01f4c29236d4154c0872f2a38
- https://git.kernel.org/stable/c/b7d1d8cb1bdca56aecebacd2896615da0acc126a


