Description
In the Linux kernel, the following vulnerability has been resolved:

ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure

The goto err label leads to:

genlmsg_cancel(skb, ehdr);
return ret;

If ethnl_tsinfo_prepare_dump() failed, it has not started a genlmsg.
There's nothing to cancel, and passing an error pointer to
genlmsg_cancel() would cause a crash.
Published: 2026-07-19
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash
Action: Apply patch
AI Analysis

Impact

The Linux kernel contains a flaw in the ethtool tsinfo-related routine. When the preparation stage fails, the code mistakenly passes an error pointer to genlmsg_cancel, attempting to cancel a message that was never started. This null pointer dereference causes a kernel panic, resulting in an immediate denial of service as the system becomes unavailable until rebooted.

Affected Systems

All Linux kernel versions that include the generic ethtool implementation before the commit that resolved the bug are affected. The provided CPE list covers every Linux kernel release and the 7.1 release candidates (rc1‑rc5). Consequently, any system running a kernel prior to the patch that contains this path is vulnerable when a user invokes ethtool to query tsinfo on a network device.

Risk and Exploitability

The flaw is exploitable by triggering a failing ethtool tsinfo call, which typically requires local execution of the ethtool utility or sufficient privileges to run it. The CVSS score of 5.5 indicates a medium severity. The EPSS score of less than 1 % denotes a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers who can invoke ethtool locally will cause a kernel crash, leading to a denial of service until the system is rebooted.

Generated by OpenCVE AI on October 8, 2026 at 19:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit which fixes the ethtool tsinfo error handling. This update removes the null pointer dereference and eliminates the crash.
  • Limit the ability to run ethtool to users with the appropriate privileges, for example by setting the file permissions of /sbin/ethtool to root only or by applying an access‑control policy such as SELinux or AppArmor to restrict its execution.
  • Check the distribution's security advisories for kernel updates that contain this patch, and install them to ensure the vulnerability is removed.

Generated by OpenCVE AI on October 8, 2026 at 19:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8593-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8603-1 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8618-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8663-1 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-8664-1 Linux kernel (NVIDIA BaseOS) vulnerabilities
Ubuntu USN Ubuntu USN USN-8728-1 Linux kernel (GCP) vulnerabilities
Ubuntu USN Ubuntu USN USN-8728-2 Linux kernel (Azure) vulnerabilities
Ubuntu USN Ubuntu USN USN-8728-3 Linux kernel (Oracle) vulnerabilities
History

Thu, 08 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo CWE-763

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*

Wed, 22 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sun, 19 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure The goto err label leads to: genlmsg_cancel(skb, ehdr); return ret; If ethnl_tsinfo_prepare_dump() failed, it has not started a genlmsg. There's nothing to cancel, and passing an error pointer to genlmsg_cancel() would cause a crash.
Title ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-07-19T14:56:08.203Z

Reserved: 2026-07-19T07:54:57.025Z

Link: CVE-2026-63986

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-19T16:17:17.847

Modified: 2026-10-08T14:47:43.260

Link: CVE-2026-63986

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-19T00:00:00Z

Links: CVE-2026-63986 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T19:15:20Z

Weaknesses
  • CWE-476

    NULL Pointer Dereference

  • CWE-763

    Release of Invalid Pointer or Reference