Linux Kernel FCoE Control VLAN Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Linux kernel's SCSI FCoE subsystem. The issue arises in the FCoE control VLAN, where the CVL walker function improperly handles FIP descriptors with a length of zero. This oversight allows an unauthenticated L2 peer to disrupt FCoE initiators by sending a malformed FIP CVL frame. The vulnerability exists in several versions of the Linux kernel.

Impact

Exploitation of this vulnerability can lead to a denial-of-service condition, where the affected FCoE initiator becomes unresponsive to subsequent FIP frames, causing a disruption in normal operations.

Reproduction

The vulnerability can be reproduced by sending a FIP CVL frame with a descriptor that has a type of 'FIP_DT_NON_CRITICAL' and a length of zero. This can be done from an unauthenticated L2 peer on the FCoE control VLAN, targeting an FCoE, QEDF, or BNX2FC initiator.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for downloading the patched version are available on the official Linux kernel website.

Added: Jul 19, 2026, 8:34 PM
Updated: Jul 19, 2026, 8:34 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.3
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.