Improper input validation in Linux kernel - CVE-2026-63985
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in fallback_set_params() in the ethtool EEPROM Netlink fallback path when processing module EEPROM read parameters. A local user can supply an offset and length combination that exceeds the EEPROM bounds to cause a denial of service.
The issue affects the Netlink fallback path for reading module EEPROM and may lead to unexpected behavior in drivers or device firmware.
How to mitigate CVE-2026-63985
Sources
- https://git.kernel.org/stable/c/0e182689831277faf2ef683573a60474c208f690
- https://git.kernel.org/stable/c/4fe1bc4b3603f621240d5b401742f302190db769
- https://git.kernel.org/stable/c/65674d2489a12b8efd2ca0effb3de1d12224b596
- https://git.kernel.org/stable/c/67cfdd9210b99f260b3e0afeb9525e0acc7be31e
- https://git.kernel.org/stable/c/6ed7ebe22e9c3e3e946b6973c1ce43d3c38aeac1
- https://git.kernel.org/stable/c/d81376053a00865c70b8d8506a1cb93f2943d413
- https://git.kernel.org/stable/c/fd0de51c54fa8474a0ddeedd71c65ad09fada390