-

CVE-2026-63890

scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker

In the Linux kernel, the following vulnerability has been resolved:

scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker

drivers/scsi/fcoe/fcoe_ctlr.c::fcoe_ctlr_recv_clr_vlink() advanced the
descriptor cursor by an attacker-supplied fip_dlen without ever
requiring dlen >= sizeof(struct fip_desc) in the default branch.  The
named descriptor cases (FIP_DT_MAC, FIP_DT_NAME, FIP_DT_VN_ID) checked
their per-type minimum lengths, but a FIP_DT_NON_CRITICAL descriptor
(fip_dtype >= 128, which the standard requires receivers to silently
ignore) skipped that check entirely.

An unauthenticated L2 peer on the FCoE control VLAN could hang
fcoe_ctlr_recv_work on an fcoe, qedf, or bnx2fc initiator indefinitely
by emitting one FIP CVL frame whose single descriptor had fip_dtype ==
FIP_DT_NON_CRITICAL and fip_dlen == 0: the cursor advanced zero bytes
per iteration and the loop condition rlen >= sizeof(*desc) stayed true
forever, blocking every subsequent FIP frame on that controller.

Tighten the outer dlen guard to also reject dlen < sizeof(struct
fip_desc), so a malformed descriptor whose length cannot even cover the
descriptor header is rejected before the switch.  This is the same
lower-bound the named cases already apply and is the minimum scope that
closes the loop.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 97c8389d54b9665c38105ea72a428a44b97ff2f6
Version < d179949d2175d2857d1c3a275a22bea58bcc5d36
Status affected
Version 97c8389d54b9665c38105ea72a428a44b97ff2f6
Version < fda976f7390bb5d1e9b84ef11ebb17323038e0c6
Status affected
Version 97c8389d54b9665c38105ea72a428a44b97ff2f6
Version < 80a0cd307205236ca28aa49bc553f58edcb9bf3a
Status affected
Version 97c8389d54b9665c38105ea72a428a44b97ff2f6
Version < 0e3c6e5a8fc15a74dfb1e0c1df9f1da73600a81a
Status affected
Version 97c8389d54b9665c38105ea72a428a44b97ff2f6
Version < 549859a1131052b07dff11a448e9f3221a40f260
Status affected
Version 97c8389d54b9665c38105ea72a428a44b97ff2f6
Version < 14dd80a20a72ce334adcc2d67402360527065948
Status affected
Version 97c8389d54b9665c38105ea72a428a44b97ff2f6
Version < d537d29d51c8b808469e5adacf3e5a0092700738
Status affected
Version 97c8389d54b9665c38105ea72a428a44b97ff2f6
Version < 9eed1bd59937e6828b00d2f2dfef631d964f3636
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 2.6.30
Status affected
Version 0
Version < 2.6.30
Status unaffected
Version <= 5.10.*
Version 5.10.259
Status unaffected
Version <= 5.15.*
Version 5.15.210
Status unaffected
Version <= 6.1.*
Version 6.1.176
Status unaffected
Version <= 6.6.*
Version 6.6.143
Status unaffected
Version <= 6.12.*
Version 6.12.93
Status unaffected
Version <= 6.18.*
Version 6.18.35
Status unaffected
Version <= 7.0.*
Version 7.0.12
Status unaffected
Version <= *
Version 7.1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.114
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d179949d2175d2857d1c3a275a22bea58bcc5d36
https://git.kernel.org/stable/c/fda976f7390bb5d1e9b84ef11ebb17323038e0c6
https://git.kernel.org/stable/c/80a0cd307205236ca28aa49bc553f58edcb9bf3a
https://git.kernel.org/stable/c/0e3c6e5a8fc15a74dfb1e0c1df9f1da73600a81a
https://git.kernel.org/stable/c/549859a1131052b07dff11a448e9f3221a40f260
https://git.kernel.org/stable/c/14dd80a20a72ce334adcc2d67402360527065948
https://git.kernel.org/stable/c/d537d29d51c8b808469e5adacf3e5a0092700738
https://git.kernel.org/stable/c/9eed1bd59937e6828b00d2f2dfef631d964f3636