Out-of-Bounds Write Vulnerability in Linux Kernel Affecting Ethernet Device Drivers
CVE-2026-63996
Currently unrated
What is CVE-2026-63996?
A vulnerability exists in the Linux kernel's handling of responses from ethernet device drivers. The issue arises when a malicious or buggy SFP module returns a response length longer than expected, resulting in potential out-of-bounds writes. This vulnerability can lead to instability in system operations and may allow exploitation via specially crafted network responses. To mitigate this risk, the kernel has added safeguards against excessive response lengths, enhancing the overall security posture of the kernel.
Affected Version(s)
Linux a39c84d796254e6b1662ca0c46dbc313379e9291 < 2f818cc98fd2c63a08239cb48995f6c3bfe9d9b3
Linux a39c84d796254e6b1662ca0c46dbc313379e9291 < 4d42fb88ec61f2e98c33a9e3a2de371d5edbc6b1
Linux a39c84d796254e6b1662ca0c46dbc313379e9291