CVE-2026-80949

Source
https://cve.org/CVERecord?id=CVE-2026-80949
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-80949.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-80949
Downstream
Related
Published
2026-09-11T19:42:19Z
Modified
2026-09-18T18:26:40Z
Summary
wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()

The memory allocated for buf is not freed in some of the error paths in brcmf_sdio_read_control(). Fix that by adding vfree() calls.

[arend: rework as suggested by Johannes]

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80949.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
dd43a01c5cdb811adeb09e6a2d2788f8aa0d0969
Fixed
b1d0a90a844abccdfed9fe141b5d0d654a821485
Fixed
86b57fa3172e287bc083113507a965e6d9a46a45
Fixed
a732c4f36a4cd79f3702391f88ebb56f2e43b0ee
Fixed
7704f6ba2a8c492b07a3eaa1e311b4b30d389246
Fixed
fdb880a7d575efe8b5c7b5b819b96d9251a3937f
Fixed
261d7c7610b4b2f476382c88a2d1ae0cc5e07add
Fixed
ba04715ee672c336272be3ceb43bda9ffc33eb75
Fixed
0d10db8e94fcb23a799789aaa696b4d8f937e207

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-80949.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.8.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-80949.json"