Executive brief
A vulnerability was identified in the Linux kernel's ethtool component, which manages network interface hardware settings. The issue occurs when reading module EEPROM data through the Netlink interface, where the system failed to properly check if the requested data range exceeded the actual hardware memory limits. This could lead to unexpected behavior in network drivers or device firmware, potentially impacting system stability.
Technical details
A vulnerability exists in the ethtool EEPROM Netlink fallback path (fallback_set_params()) in the Linux kernel. While the code validated that the starting offset was within the EEPROM length, it failed to verify that the combined offset and length remained within bounds. This lack of bounds checking could result in out-of-bounds reads or 'surprises' for underlying drivers and device firmware. Additionally, the eeprom_fallback() function used kmalloc() instead of kzalloc(), potentially leaving buffers uninitialized. The fix adds the missing offset+length validation and switches to kzalloc() for buffer allocation. This affects kernels from version 5.13 onwards until patched in various stable branches (5.15.210, 6.1.100, 6.6.41, 6.9.10, etc.).
Affected products
- Linux Linux 5.13 to 5.15.210, 6.1.100, 6.6.41, 6.9.10, 6.10-rc1
Timeline
- 2026-07-19: disclosed: CVE published via NVD
References
- https://git.kernel.org/stable/c/0e182689831277faf2ef683573a60474c208f690
- https://git.kernel.org/stable/c/4fe1bc4b3603f621240d5b401742f302190db769
- https://git.kernel.org/stable/c/65674d2489a12b8efd2ca0effb3de1d12224b596
- https://git.kernel.org/stable/c/67cfdd9210b99f260b3e0afeb9525e0acc7be31e
- https://git.kernel.org/stable/c/6ed7ebe22e9c3e3e946b6973c1ce43d3c38aeac1
- https://git.kernel.org/stable/c/d81376053a00865c70b8d8506a1cb93f2943d413
- https://git.kernel.org/stable/c/fd0de51c54fa8474a0ddeedd71c65ad09fada390