Vulnerability in Linux Kernel Affecting Ethtool Functionality
CVE-2026-63987

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63987?

A vulnerability exists in the Linux Kernel within the Ethtool component, where the profile updates are not correctly bounded. Specifically, the function ethnl_update_profile() processes the nested list for IRQ moderation without adequate safeguards for the index used, allowing an attacker to manipulate the number of nested entries. This oversight could lead to potential memory corruption due to the mishandling of user-controlled input, necessitating careful attention to user input validation within the kernel.

Affected Version(s)

Linux f750dfe825b904164688adeb147950e0e0c4d262

Linux f750dfe825b904164688adeb147950e0e0c4d262 < 0c02c190bcd9822477038ff2cee10ea584ac1b1d

Linux f750dfe825b904164688adeb147950e0e0c4d262 < 6205f7166d2dd14a017a5802c81e5bd1421a8635

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.