Security Advisory

CVE-2025-37990

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-05-20 17:18:45
Last updated 2026-05-11 21:19:10
Assigner Linux
State PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage() The function brcmf_usb_dl_writeimage() calls the function brcmf_usb_dl_cmd() but dose not check its return value. The state.state and the state.bytes are uninitialized if the function brcmf_usb_dl_cmd() fails. It is dangerous to use uninitialized variables in the conditions. Add error handling for brcmf_usb_dl_cmd() to jump to error handling path if the brcmf_usb_dl_cmd() fails and the state.state and the state.bytes are uninitialized. Improve the error message to report more detailed error information.