-

CVE-2026-63997

ethtool: module: avoid leaking a netdev ref on module flash errors

In the Linux kernel, the following vulnerability has been resolved:

ethtool: module: avoid leaking a netdev ref on module flash errors

module_flash_fw_schedule() is missing undo for setting
the "in_progress" flag and taking the netdev reference.
Delay taking these, the device can't disappear while
we are holding rtnl_lock.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e
Version < f7b4513e77f9571dc1041a798b93b5c4a4bfc191
Status affected
Version 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e
Version < 61848c83b9132ab839809fe415ba7802a0aca4f6
Status affected
Version 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e
Version < 956b134d917fd7e014dc7e39a9b7610c04fcc9ba
Status affected
Version 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e
Version < fb7f511d62692661846c47f199e0afe25c2982db
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.11
Status affected
Version 0
Version < 6.11
Status unaffected
Version <= 6.12.*
Version 6.12.93
Status unaffected
Version <= 6.18.*
Version 6.18.35
Status unaffected
Version <= 7.0.*
Version 7.0.12
Status unaffected
Version <= *
Version 7.1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.064
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f7b4513e77f9571dc1041a798b93b5c4a4bfc191
https://git.kernel.org/stable/c/61848c83b9132ab839809fe415ba7802a0aca4f6
https://git.kernel.org/stable/c/956b134d917fd7e014dc7e39a9b7610c04fcc9ba
https://git.kernel.org/stable/c/fb7f511d62692661846c47f199e0afe25c2982db