Linux Kernel Vulnerability in Ethtool Module Related to Netdev Reference Management
CVE-2026-63997
What is CVE-2026-63997?
A vulnerability in the Linux kernel's ethtool module has been identified, which involves improper management of netdev references during module flash operations. Specifically, the function module_flash_fw_schedule() fails to appropriately undo the setting of the 'in_progress' flag and the acquisition of a netdev reference in the event of a flash error. This could potentially lead to security imperfections allowing devices to disappear while under lock, thereby complicating reference management and increasing the risk of system instability.
Affected Version(s)
Linux 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e
Linux 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e < 61848c83b9132ab839809fe415ba7802a0aca4f6
Linux 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e < 956b134d917fd7e014dc7e39a9b7610c04fcc9ba