Linux Kernel Out-of-Bounds Write Vulnerability in Ethtool CMIS CDB Reply Length Handling

Vulnerability

A vulnerability in the Linux kernel's handling of CDB replies in the ethtool CMIS module can lead to out-of-bounds writes. This issue arises because a malicious or faulty SFP module could send a reply length longer than what the kernel expects, potentially overwriting memory and causing instability. While the threat from malicious hardware is theoretical, some modules could be buggy or misread, making this a valid concern. The vulnerability affects the Linux kernel stable tree.

Impact

The vulnerability can be exploited to cause out-of-bounds writes, which can lead to memory corruption and potentially allow for arbitrary code execution or escalation of privileges.

Reproduction

The vulnerability can be reproduced by using an SFP module that either responds with an exaggerated reply length or one that is known to be faulty, in conjunction with a version of the Linux kernel that is prior to the patch.

Remediation

Users can upgrade to the latest version of the Linux kernel stable tree to address this vulnerability.

Added: Jul 19, 2026, 7:00 PM
Updated: Jul 19, 2026, 7:00 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
4.3
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.