Linux Kernel Vulnerability in Ethtool Module Related to Netdev Reference Management
CVE-2026-63997

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63997?

A vulnerability in the Linux kernel's ethtool module has been identified, which involves improper management of netdev references during module flash operations. Specifically, the function module_flash_fw_schedule() fails to appropriately undo the setting of the 'in_progress' flag and the acquisition of a netdev reference in the event of a flash error. This could potentially lead to security imperfections allowing devices to disappear while under lock, thereby complicating reference management and increasing the risk of system instability.

Affected Version(s)

Linux 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e

Linux 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e < 61848c83b9132ab839809fe415ba7802a0aca4f6

Linux 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e < 956b134d917fd7e014dc7e39a9b7610c04fcc9ba

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.