Back to overview

CVE-2026-63997

Description
In the Linux kernel, the following vulnerability has been resolved: ethtool: module: avoid leaking a netdev ref on module flash errors module_flash_fw_schedule() is missing undo for setting the "in_progress" flag and taking the netdev reference. Delay taking these, the device can't disappear while we are holding rtnl_lock.

Metadata

CVE ID
CVE-2026-63997
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 14:56 UTC
Last updated
2026-07-19 14:56 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e < f7b4513e77f9571dc1041a798b93b5c4a4bfc191, 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e < 61848c83b9132ab839809fe415ba7802a0aca4f6, 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e < 956b134d917fd7e014dc7e39a9b7610c04fcc9ba, 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e < fb7f511d62692661846c47f199e0afe25c2982db
Linux Linux 6.11, 0 < 6.11, 6.12.93 ≤ 6.12.*, 6.18.35 ≤ 6.18.* …
Back to overview