{"id":"CVE-2026-63995","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: cmis: validate start_cmd_payload_size from module\n\nThe CMIS firmware update code reads start_cmd_payload_size from\nthe module's FW Management Features CDB repl…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: cmis: validate start_cmd_payload_size from module\n\nThe CMIS firmware update code reads start_cmd_payload_size from\nthe module's FW Management Features CDB repl…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-787"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 6.11, < 6.12.93","linux_kernel >= 6.13, < 6.18.35","linux_kernel >= 6.19, < 7.0.12","linux_kernel = 7.1"],"patched":["linux_kernel 7.0.12"],"published":"2026-07-19","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:26:18.313","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63995","references":[{"url":"https://git.kernel.org/stable/c/0696709e951be54c699664adf546d16e28974d53","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/12c2496a71f82f63617971ca9b730dffa05cf58b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/63112b4515469d00008452d9cfe3fb3bf1aa2df3","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a46340da00385be7fb16c62425ebc20006f2d5d8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd"],"epss":0.00129,"epssPercentile":0.02145,"ingestedAt":"2026-10-07T20:46:46.958Z","slug":"CVE-2026-63995","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nethtool: cmis: validate start_cmd_payload_size from module\n\nThe CMIS firmware update code reads start_cmd_payload_size from\nthe module's FW Management Features CDB reply and uses it directly\nas the byte count for memcpy. The destination buffer is 112 bytes\n(ETHTOOL_CMIS_CDB_LPL_MAX_PL_LENGTH - 8). So a malicious\nmodule (or corrupted response) can cause a OOB write later on in\ncmis_fw_update_start_download().\n\nLet's error out. If modules that expect longer LPL writes actually\nexist we should revisit.\n\nstruct cmis_cdb_start_fw_download_pl's definition has to move,\nno change there.\n\n## Affected\n\n- `linux_kernel >= 6.11, < 6.12.93`\n- `linux_kernel >= 6.13, < 6.18.35`\n- `linux_kernel >= 6.19, < 7.0.12`\n- `linux_kernel = 7.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 7.0.12`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}