Broadcom brcmfmac driver is vulnerable to a frame validation bypass
Published Jan 16, 2020
8.3
HIGHCVSS 3.1
EPSS 3.29%
Description
The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass. If the brcmfmac driver receives a firmware event frame from a remote source, the is_wlc_event_frame function will cause this frame to be discarded and unprocessed. If the driver receives the firmware event frame from the host, the appropriate handler is called. This frame validation can be bypassed if the bus used is USB (for instance by a wifi dongle). This can allow firmware event frames from a remote source to be processed. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.
Affected products
-
- Version commit prior to a4176ec356c73a46c07c181c6d04039fafa34a9fStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Broadcom | brcmfmac WiFi driver | n/a |
|
Configuration 1
- n/a
Configuration 2
- 6.0
- 7.0
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1127.el7
Fixed · RHSA-2020:1016
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1127.rt56.1093.el7
Fixed · RHSA-2020:1070
Red Hat Enterprise Linux 7.7 Extended Update Support
kernel-0:3.10.0-1062.26.1.el7
Fixed · RHSA-2020:2522
Red Hat Enterprise Linux 8
kernel-0:4.18.0-80.11.1.el8_0
Fixed · RHSA-2019:2703
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-80.11.1.rt9.156.el8_0
Fixed · RHSA-2019:2741
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Will not fix
Red Hat Enterprise Linux 7
kernel-alt
Will not fix
Red Hat Enterprise MRG 2
kernel-rt
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1127.el7 | Fixed | RHSA-2020:1016 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1127.rt56.1093.el7 | Fixed | RHSA-2020:1070 |
| Red Hat Enterprise Linux 7.7 Extended Update Support | kernel-0:3.10.0-1062.26.1.el7 | Fixed | RHSA-2020:2522 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-80.11.1.el8_0 | Fixed | RHSA-2019:2703 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-80.11.1.rt9.156.el8_0 | Fixed | RHSA-2019:2741 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Will not fix | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a4176ec356c73a46c07c181c6d04039fafa34a9f
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
1 other source (CVE.org) ▾
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
AV:A/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.29% (0.03286) | 88.06th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.31% (0.03313) | 86.93th | v5 (v2026.06.15) |
| Mar 21, 2026 | 0.51% (0.00514) | 66.34th | v4 (v2025.03.14) |
| Nov 18, 2025 | 1.76% (0.01765) | 81.13th | v4 (v2025.03.14) |
| Mar 30, 2025 | 0.47% (0.00466) | 61.52th | v4 (v2025.03.14) |
| Mar 29, 2025 | 6.42% (0.06416) | 84.62th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.47% (0.00466) | 62.34th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.18% (0.00177) | 56.15th | v3 (v2023.03.01) |
| Dec 23, 2023 | 0.18% (0.00177) | 54.89th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.15% (0.00155) | 49.98th | v3 (v2023.03.01) |
| Mar 6, 2023 | 11.15% (0.11152) | 94.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 11.15% (0.11152) | 94.45th | v2 (v2022.01.01) |
| Feb 19, 2022 | 39.08% (0.39082) | 97.35th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.39% (0.12388) | 89.46th | v2 (v2022.01.01) |
| Feb 3, 2022 | 7.71% (0.07710) | 84.59th | v1 |
| Jan 6, 2022 | 7.71% (0.07710) | 84.41th | v1 |
| Sep 1, 2021 | 1.83% (0.01828) | 74.99th | v1 |
| Apr 14, 2021 | 1.83% (0.01828) | 0.00th | v1 |
References (12)
- https://access.redhat.com/security/cve/CVE-2019-9503 Vendor Advisory
- https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html x_refsource_MISCThird Party Advisory
- https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html#cve-2019-9503-remotely-sending-firmware-events-bypassing-is-wlc-event-frame
- https://bugzilla.redhat.com/show_bug.cgi?id=1701842 x_refsource_MISCIssue TrackingThird Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1132828 x_refsource_MISCIssue TrackingThird Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a4176ec356c73a46c07c181c6d04039fafa34a9f x_refsource_MISCPatchThird Party Advisory
- https://kb.cert.org/vuls/id/166939/ x_refsource_MISCThird Party AdvisoryUS Government Resource
- https://nvd.nist.gov/vuln/detail/CVE-2019-9503
- https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-9503.html x_refsource_MISCThird Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2019-9503 x_refsource_MISCThird Party Advisory
- https://www.bleepingcomputer.com/news/security/broadcom-wifi-driver-flaws-expose-computers-phones-iot-to-rce-attacks/
- https://www.cve.org/CVERecord?id=CVE-2019-9503
Change history (0)
No recorded changes yet.