๐Ÿ” CVE Alert

CVE-2026-68403

UNKNOWN 0.0

wifi: brcmfmac: initialize SDIO data work before cleanup

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: initialize SDIO data work before cleanup brcmf_sdio_probe() stores the newly allocated bus in sdiodev->bus before allocating the ordered workqueue. If that allocation fails, the function jumps to fail and calls brcmf_sdio_remove(). brcmf_sdio_remove() unconditionally cancels bus->datawork. Initialize the work item before the first failure path that can reach brcmf_sdio_remove(), so the cleanup path always observes a valid work object. This issue was found by our static analysis tool and then confirmed by manual review of the probe error path and the remove-time work drain. The problem pattern is an early setup failure that reaches a cleanup helper which cancels an embedded work item before its initializer has run. A QEMU PoC forced alloc_ordered_workqueue() to fail at the same point in brcmf_sdio_probe(), before INIT_WORK(&bus->datawork) is reached. The resulting fail path calls brcmf_sdio_remove(), and DEBUG_OBJECTS reports the invalid work drain with brcmf_sdio_probe() and brcmf_sdio_remove() in the stack.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
9982464379e81ece51ced03ebecbbcd34ea367a6 < f50a2b9e57a751e70ae9a272875d80d39eaccd6a 9982464379e81ece51ced03ebecbbcd34ea367a6 < 6bd21ec8549a5854dd64204a66289952917a924c 9982464379e81ece51ced03ebecbbcd34ea367a6 < 5c342437ea44bb829680ca9e4f683dd5b325b219 9982464379e81ece51ced03ebecbbcd34ea367a6 < c73c3fc1c7ca5a927639f0884624cb244ba791e4 9982464379e81ece51ced03ebecbbcd34ea367a6 < 2a665946e0407a05a3f81bd56a08553c446498e0
Linux / Linux
4.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f50a2b9e57a751e70ae9a272875d80d39eaccd6a git.kernel.org: https://git.kernel.org/stable/c/6bd21ec8549a5854dd64204a66289952917a924c git.kernel.org: https://git.kernel.org/stable/c/5c342437ea44bb829680ca9e4f683dd5b325b219 git.kernel.org: https://git.kernel.org/stable/c/c73c3fc1c7ca5a927639f0884624cb244ba791e4 git.kernel.org: https://git.kernel.org/stable/c/2a665946e0407a05a3f81bd56a08553c446498e0