CVE-2026-63995

Source
https://cve.org/CVERecord?id=CVE-2026-63995
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63995.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63995
Downstream
Published
2026-07-19T14:56:14.580Z
Modified
2026-07-22T05:29:45.895074764Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ethtool: cmis: validate start_cmd_payload_size from module
Details

In the Linux kernel, the following vulnerability has been resolved:

ethtool: cmis: validate startcmdpayload_size from module

The CMIS firmware update code reads startcmdpayloadsize from the module's FW Management Features CDB reply and uses it directly as the byte count for memcpy. The destination buffer is 112 bytes (ETHTOOLCMISCDBLPLMAXPLLENGTH - 8). So a malicious module (or corrupted response) can cause a OOB write later on in cmisfwupdatestart_download().

Let's error out. If modules that expect longer LPL writes actually exist we should revisit.

struct cmiscdbstartfwdownload_pl's definition has to move, no change there.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63995.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c4f78134d45c9619339c96b4bea380b1d0699788
Fixed
63112b4515469d00008452d9cfe3fb3bf1aa2df3
Fixed
0696709e951be54c699664adf546d16e28974d53
Fixed
a46340da00385be7fb16c62425ebc20006f2d5d8
Fixed
12c2496a71f82f63617971ca9b730dffa05cf58b

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63995.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.12.93
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63995.json"