CVE-2026-63997

UnknownEPSS 0.17%

Last modified

CVE-2026-63997 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ethtool: module: avoid leaking a netdev ref on module flash errors module_flash_fw_schedule() is missing undo for setting the "in_progress" flag and taking the netdev reference. Delay taking these, the device can't disappear while we are holding rtnl_lock.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: ethtool: module: avoid leaking a netdev ref on module flash errors module_flash_fw_schedule() is missing undo for setting the "in_progress" flag and taking the netdev reference. Delay taking these, the device can't disappear while we are holding rtnl_lock.

Metrics

EPSS Probability
0.17%

6.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e, < f7b4513e77f9571dc1041a798b93b5c4a4bfc191; >= 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e, < 61848c83b9132ab839809fe415ba7802a0aca4f6; >= 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e, < 956b134d917fd7e014dc7e39a9b7610c04fcc9ba; >= 32b4c8b53ee7799e34a2b1634d32d3ce1e36c44e, < fb7f511d62692661846c47f199e0afe25c2982db
LinuxLinux6.11

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-63997?
In the Linux kernel, the following vulnerability has been resolved: ethtool: module: avoid leaking a netdev ref on module flash errors module_flash_fw_schedule() is missing undo for setting the "in_progress" flag and taking the netdev reference. Delay taking these, the device can't disappear while we are holding rtnl_lock.
How severe is CVE-2026-63997?
Severity scoring for CVE-2026-63997 is pending analysis. The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2026-63997?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-63997?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST