Out-of-Bounds Write Vulnerability in Linux Kernel's Ethtool for CMIS Firmware
CVE-2026-63995
What is CVE-2026-63995?
A notable vulnerability in the Linux Kernel arises from the Ethtool handling of commands related to CMIS firmware updates. Specifically, the start_cmd_payload_size parameter is extracted from a firmware management feature response and directly utilized as a byte count in a memory copy operation. This approach inadequately checks the validity of the input, allowing for potential out-of-bounds writes if a malicious module or corrupted response is encountered. Such scenarios result in memory corruption, potentially affecting system stability and integrity during firmware downloads. It is crucial for users to ensure that their systems are updated with the latest patches to mitigate this risk.
Affected Version(s)
Linux c4f78134d45c9619339c96b4bea380b1d0699788 < 63112b4515469d00008452d9cfe3fb3bf1aa2df3
Linux c4f78134d45c9619339c96b4bea380b1d0699788 < 0696709e951be54c699664adf546d16e28974d53
Linux c4f78134d45c9619339c96b4bea380b1d0699788