REDHAT-BUG-2348656: Low severity Linux Kernel vulnerability

Published Feb 27, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: brcmfmac: Check the return value of ofpropertyreadstringindex()

Somewhen between 6.10 and 6.11 the driver started to crash on my MacBookPro14,3. The property doesn't exist and 'tmp' remains uninitialized, so we pass a random pointer to devmkstrdup().

The crash I am getting looks like this:

BUG: unable to handle page fault for address: 00007f033c669379 PF: supervisor read access in kernel mode PF: errorcode(0x0001) - permissions violation PGD 8000000101341067 P4D 8000000101341067 PUD 101340067 PMD 1013bb067 PTE 800000010aee9025 Oops: Oops: 0001 [#1] SMP PTI CPU: 4 UID: 0 PID: 827 Comm: (udev-worker) Not tainted 6.11.8-gentoo #1 Hardware name: Apple Inc. MacBookPro14,3/Mac-551B86E5744E2388, BIOS 529.140.2.0.0 06/23/2024 RIP: 0010:strlen+0x4/0x30 Code: f7 75 ec 31 c0 c3 cc cc cc cc 48 89 f8 c3 cc cc cc cc 0f 1f 40 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa <80> 3f 00 74 14 48 89 f8 48 83 c0 01 80 38 00 75 f7 48 29 f8 c3 cc RSP: 0018:ffffb4aac0683ad8 EFLAGS: 00010202 RAX: 00000000ffffffea RBX: 00007f033c669379 RCX: 0000000000000001 RDX: 0000000000000cc0 RSI: 00007f033c669379 RDI: 00007f033c669379 RBP: 00000000ffffffea R08: 0000000000000000 R09: 00000000c0ba916a R10: ffffffffffffffff R11: ffffffffb61ea260 R12: ffff91f7815b50c8 R13: 0000000000000cc0 R14: ffff91fafefffe30 R15: ffffb4aac0683b30 FS: 00007f033ccbe8c0(0000) GS:ffff91faeed00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f033c669379 CR3: 0000000107b1e004 CR4: 00000000003706f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <TASK> ? die+0x23/0x70 ? pagefaultoops+0x149/0x4c0 ? rawspinrqlocknested+0xe/0x20 ? schedbalancenewidle+0x22b/0x3c0 ? updateloadavg+0x78/0x770 ? excpagefault+0x6f/0x150 ? asmexcpagefault+0x26/0x30 ? pfxpciconf1write+0x10/0x10 ? strlen+0x4/0x30 devmkstrdup+0x25/0x70 brcmfofprobe+0x273/0x350 [brcmfmac]

Affected Software

1 affected component
Linux Kernel

Event History

Feb 27, 2025
Data Sourced
via Red Hat·03:06 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2348656?

The severity of REDHAT-BUG-2348656 is classified based on the potential impact on kernel stability and device reliability.

2

How do I fix REDHAT-BUG-2348656?

To fix REDHAT-BUG-2348656, update your Linux kernel to version 6.11 or later where the vulnerability has been addressed.

3

What systems are affected by REDHAT-BUG-2348656?

REDHAT-BUG-2348656 affects Linux kernel versions between 6.10 and 6.11, particularly impacting systems using the brcmfmac driver.

4

What specific issue does REDHAT-BUG-2348656 address?

REDHAT-BUG-2348656 addresses a vulnerability in the brcmfmac Wi-Fi driver related to an uninitialized return value leading to crashes.

5

Is there a workaround for REDHAT-BUG-2348656?

Currently, the recommended action is to update the kernel, as there are no known safe workarounds for REDHAT-BUG-2348656.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203