---
id: CVE-2026-63996
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ethtool: cmis: require exact CDB reply length

  Malicious SFP module could respond with rpl_len longer than
  what cmis_cdb_process_reply() expected, leading to OOB writes…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ethtool: cmis: require exact CDB reply length

  Malicious SFP module could respond with rpl_len longer than
  what cmis_cdb_process_reply() expected, leading to OOB writes…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.11, < 6.12.93'
  - 'linux_kernel >= 6.13, < 6.18.35'
  - 'linux_kernel >= 6.19, < 7.0.12'
  - linux_kernel = 7.1
patched:
  - linux_kernel 7.0.12
published: '2026-07-19'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T19:58:45.670'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-63996'
references:
  - url: 'https://git.kernel.org/stable/c/2f818cc98fd2c63a08239cb48995f6c3bfe9d9b3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4d42fb88ec61f2e98c33a9e3a2de371d5edbc6b1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6c3f999a9d1338c6c89a9ff4549eafe72bc2e7b1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/eb5dcd740cd7fa27bc2caeff2d28ef28e93ff4d3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00129
epssPercentile: 0.0213
ingestedAt: '2026-10-02T22:33:09.809Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ethtool: cmis: require exact CDB reply length

Malicious SFP module could respond with rpl_len longer than
what cmis_cdb_process_reply() expected, leading to OOB writes.
Malicious HW is a bit theoretical but some modules may just
be buggy and/or the reads may occasionally get corrupted,
so let's protect the kernel.

The existing check protects from short replies. We need to
protect from long ones, too. All callers that pass a non-zero
rpl_exp_len cast the reply payload to a fixed-layout struct
and read fields at fixed offsets, with no version negotiation
or short-reply handling:

  - cmis_cdb_validate_password()
  - cmis_cdb_module_features_get()
  - cmis_fw_update_fw_mng_features_get()

so let's assume that responses longer than expected do not
have to be handled gracefully here. Add a warning message
to make the debug easier in case my understanding is wrong...

Note that page_data->length (argument of kmalloc) comes from
last arg to ethtool_cmis_page_init() which is rpl_exp_len.

Note2 that AIs also like to point out overflows in args->req.payload
itself (which is a fixed-size 120 B buffer, on the stack),
but callers should be reading structs defined by the standard,
so protecting from requests for more data than max seem like
defensive programming.

## Affected

- `linux_kernel >= 6.11, < 6.12.93`
- `linux_kernel >= 6.13, < 6.18.35`
- `linux_kernel >= 6.19, < 7.0.12`
- `linux_kernel = 7.1`

## Remediation

Upgrade past the affected range:

- `linux_kernel 7.0.12`
