Wind River Support Network

HomeDefectsLIN1022-19090
Fixed

LIN1022-19090 : Security Advisory - linux - CVE-2023-53715

Created: Oct 23, 2025    Updated: Oct 26, 2025
Resolved Date: Oct 26, 2025
Found In Version: 10.22.33.1
Fix Version: 10.22.33.10
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:[EOL][EOL]wifi: brcmfmac: cfg80211: Pass the PMK in binary instead of hex[EOL][EOL]Apparently the hex passphrase mechanism does not work on newer[EOL]chips/firmware (e.g. BCM4387). It seems there was a simple way of[EOL]passing it in binary all along, so use that and avoid the hexification.[EOL][EOL]OpenBSD has been doing it like this from the beginning, so this should[EOL]work on all chips.[EOL][EOL]Also clear the structure before setting the PMK. This was leaking[EOL]uninitialized stack contents to the device.

CVEs


Live chat
Online