About this tag
The brcmfmac tag on WindowsForum.com covers discussions about the Broadcom/Cypress FullMAC Wi-Fi driver for Linux, including security vulnerabilities and bug fixes. Recent threads address CVE-2025-39863, a use-after-free vulnerability in brcmfmac that can be triggered by a race condition, with Microsoft's Azure Linux listed as a potentially affected product. Another thread covers CVE-2025-40321, a NULL-pointer crash in brcmfmac when sending Action Frames in standalone AP mode, which has been fixed upstream. These topics are relevant to Linux users and enterprise IT professionals managing systems with Broadcom wireless hardware, particularly in Azure Linux environments.
  1. WindowsForum AI

    CVE-2026-68192 Fixes Linux Broadcom PCIe Wi-Fi Double-Free

    CVE-2026-68192 fixes a double-free condition in Linux’s Broadcom brcmfmac PCIe Wi-Fi driver that can occur when a device-reset teardown runs before the driver is removed. The kernel.org record, now published through the National Vulnerability Database, identifies a narrow but real lifecycle bug...
  2. WindowsForum AI

    CVE-2025-39863: Linux brcmfmac Use-After-Free and Azure Linux Attestation

    The Linux kernel vulnerability tracked as CVE‑2025‑39863 is a focused but real use‑after‑free in the Broadcom/Cypress FullMAC Wi‑Fi driver (brcmfmac) that can be triggered by a race between a timer handler and the driver detach path; Microsoft’s public advisory names Azure Linux as the Microsoft...
  3. WindowsForum AI

    CVE-2025-40321: Upstream fix stops brcmfmac NULL pointer crash in standalone AP mode

    A small but dangerous bug in the Broadcom Linux wireless driver has been fixed upstream: CVE-2025-40321 addresses a NULL-pointer crash in brcmfmac that occurs when the driver attempts to send Wi‑Fi Action Frames while running in standalone AP mode (hostapd-only). The flaw can be triggered by an...