Vulnerability in Linux Kernel Affecting Ethtool Functionality
CVE-2026-63987
Currently unrated
What is CVE-2026-63987?
A vulnerability exists in the Linux Kernel within the Ethtool component, where the profile updates are not correctly bounded. Specifically, the function ethnl_update_profile() processes the nested list for IRQ moderation without adequate safeguards for the index used, allowing an attacker to manipulate the number of nested entries. This oversight could lead to potential memory corruption due to the mishandling of user-controlled input, necessitating careful attention to user input validation within the kernel.
Affected Version(s)
Linux f750dfe825b904164688adeb147950e0e0c4d262
Linux f750dfe825b904164688adeb147950e0e0c4d262 < 0c02c190bcd9822477038ff2cee10ea584ac1b1d
Linux f750dfe825b904164688adeb147950e0e0c4d262 < 6205f7166d2dd14a017a5802c81e5bd1421a8635