CVE-2026-63997

Source
https://cve.org/CVERecord?id=CVE-2026-63997
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63997.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63997
Downstream
Published
2026-07-19T14:56:15.965Z
Modified
2026-07-21T03:47:45.666312024Z
Summary
ethtool: module: avoid leaking a netdev ref on module flash errors
Details

In the Linux kernel, the following vulnerability has been resolved:

ethtool: module: avoid leaking a netdev ref on module flash errors

moduleflashfwschedule() is missing undo for setting the "inprogress" flag and taking the netdev reference. Delay taking these, the device can't disappear while we are holding rtnl_lock.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63997.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e
Fixed
f7b4513e77f9571dc1041a798b93b5c4a4bfc191
Fixed
61848c83b9132ab839809fe415ba7802a0aca4f6
Fixed
956b134d917fd7e014dc7e39a9b7610c04fcc9ba
Fixed
fb7f511d62692661846c47f199e0afe25c2982db

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63997.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.12.93
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63997.json"