CVE-2026-98350EPSS p8.6%
CVE-2026-98350CVE-2026-98350
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: cyw: pass PMKID to firmware if present
Zero out auth_status on initialization. Otherwise, garbage will
leak from the stack to the firmware (when ssid is less than 32 bytes
and/or when params->pmkid is set). Then, pass the params->pmkid to the
firmware (without it, the firmware caches a garbage PMKID on successful
authentication and denies a subsequent association request that includes
the PMKID).
Scoring
| EPSS | 0.20% probability of exploitation · percentile 8.6% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-06 |