CVE-2023-47233: Linux Kernel
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The brcm80211 component in the Linux kernel through 6.5.10 has a brcmf_cfg80211_detach use-after-free in the device unplugging (disconnect the USB by hotplug) code. For physically proximate attackers with local access, this "could be exploited in a real world scenario." This is related to brcmf_cfg80211_escan_timeout_worker in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c.
Affected products
- Linux Linux Kernel: up to and including 6.5.10
Published 2023-11-03. Last modified 2026-06-17.