Vulnerability in Linux Kernel Affecting EEPROM Netlink Functionality
CVE-2026-63985

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63985?

A vulnerability in the Linux kernel's eeprom Netlink fallback method has been identified, which fails to properly validate the combined offset and length. This oversight may lead to unexpected behavior in drivers and device firmware, potentially causing system instability. The issue has been rectified by implementing additional checks to ensure that the sum of the offset and length remains within permissible limits. Furthermore, improvements have been made to buffer initialization routines, enhancing overall security.

Affected Version(s)

Linux 96d971e307cc0e434f96329b42bbd98cfbca07d2 < 0e182689831277faf2ef683573a60474c208f690

Linux 96d971e307cc0e434f96329b42bbd98cfbca07d2 < 6ed7ebe22e9c3e3e946b6973c1ce43d3c38aeac1

Linux 96d971e307cc0e434f96329b42bbd98cfbca07d2 < 65674d2489a12b8efd2ca0effb3de1d12224b596

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.