CVE-2023-47233
Linux Kernel vulnerability analysis and mitigation

Overview

The Linux kernel through version 6.5.10 contains a use-after-free vulnerability (CVE-2023-47233) in the brcm80211 component, specifically in the brcmfcfg80211detach function during device unplugging (USB hotplug disconnect) operations. The vulnerability is related to the brcmfcfg80211escantimeoutworker in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c (NVD, Ubuntu).

Technical details

The vulnerability occurs due to a race condition in the device removal process. When a USB device is unplugged, the brcmfusbdisconnect function initiates a cleanup chain through brcmfusbdisconnectcb, brcmfdetach, and brcmfcfg80211detach, ultimately freeing the cfg structure. However, the timeout worker may still be running when this occurs, leading to a use-after-free condition in brcmfcfg80211escantimeoutworker. The vulnerability has been assigned a CVSS v3.1 base score of 4.3 (Medium) with vector AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

The vulnerability can be exploited by physically proximate attackers with local access to cause a denial of service (system crash). The impact is limited to availability, with no direct impact on confidentiality or integrity (Ubuntu).

Mitigation and workarounds

A fix has been developed and committed to the Linux kernel. The patch involves properly handling the cleanup sequence by adding timer deletion and worker cancellation in brcmfcfg80211detach. The fix was committed with ID 0f7352557a35ab7888bc7831411ec8a3cbe20d78 and has been backported to various stable kernel versions (Kernel Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40205HIGH7.8
  • Linux KernelLinux Kernel
  • linux-gcp-5.4
NoYesNov 12, 2025
CVE-2025-40211HIGH7.1
  • Linux KernelLinux Kernel
  • linux-gcp-6.8
NoYesNov 21, 2025
CVE-2025-40206MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-modules-extra
NoYesNov 12, 2025
CVE-2025-40210MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules
NoYesNov 21, 2025
CVE-2025-40212N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesNov 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management