Improper input validation in Linux kernel - CVE-2026-63890
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in fcoe_ctlr_recv_clr_vlink() in drivers/scsi/fcoe/fcoe_ctlr.c when processing FIP CVL frames. A remote attacker can send a crafted FIP CVL frame with a zero-length non-critical descriptor to cause a denial of service.
Exploitation is limited to an unauthenticated layer 2 peer on the FCoE control VLAN and can block subsequent FIP frames on the affected controller.
How to mitigate CVE-2026-63890
Sources
- https://git.kernel.org/stable/c/0e3c6e5a8fc15a74dfb1e0c1df9f1da73600a81a
- https://git.kernel.org/stable/c/14dd80a20a72ce334adcc2d67402360527065948
- https://git.kernel.org/stable/c/549859a1131052b07dff11a448e9f3221a40f260
- https://git.kernel.org/stable/c/80a0cd307205236ca28aa49bc553f58edcb9bf3a
- https://git.kernel.org/stable/c/9eed1bd59937e6828b00d2f2dfef631d964f3636
- https://git.kernel.org/stable/c/d179949d2175d2857d1c3a275a22bea58bcc5d36
- https://git.kernel.org/stable/c/d537d29d51c8b808469e5adacf3e5a0092700738
- https://git.kernel.org/stable/c/fda976f7390bb5d1e9b84ef11ebb17323038e0c6