In the Linux kernel, the following vulnerability has been resolved: ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES… (CVE-2026-63987)
In the Linux kernel, the following vulnerability has been resolved: ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES ethnl_update_profile() walks the ETHTOOL_A_PROFILE_IRQ_MODERATION nest list with an index 'i' and writes new_profile[i++] without bounding i. The destination is kmemdup()'d at NET_DIM_PARAMS_NUM_PROFILES entries (5), but the Netlink nest count is entirely user-controlled. Netlink policies do not have support for constraining the number of nested entries (or number of multi-attr entries).
AI Analysis
Technical Summary
The Linux kernel vulnerability CVE-2026-63987 concerns the ethtool coalesce feature where the ethlnl_update_profile() function iterates over the ETHTOOL_A_PROFILE_IRQ_MODERATION nested Netlink attributes using an index 'i' to write new profile data. The index 'i' is not properly bounded, allowing writes beyond the allocated buffer size, which is fixed at NET_DIM_PARAMS_NUM_PROFILES (5 entries). Since Netlink policies do not constrain the number of nested entries, a user-controlled Netlink message can cause out-of-bounds memory writes. This vulnerability has been resolved in the Linux kernel.
Potential Impact
The vulnerability allows a user to send a crafted Netlink message with more nested profile entries than the kernel expects, potentially causing out-of-bounds memory writes. This could lead to memory corruption, which might be exploitable for privilege escalation or denial of service. However, no known exploits in the wild have been reported.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel. Users and administrators should apply the official kernel updates that include this patch. Since this is a kernel-level vulnerability, updating to a patched kernel version is the recommended remediation. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor or Linux kernel advisory for the exact fixed versions and update accordingly.
In the Linux kernel, the following vulnerability has been resolved: ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES… (CVE-2026-63987)
Description
In the Linux kernel, the following vulnerability has been resolved: ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES ethnl_update_profile() walks the ETHTOOL_A_PROFILE_IRQ_MODERATION nest list with an index 'i' and writes new_profile[i++] without bounding i. The destination is kmemdup()'d at NET_DIM_PARAMS_NUM_PROFILES entries (5), but the Netlink nest count is entirely user-controlled. Netlink policies do not have support for constraining the number of nested entries (or number of multi-attr entries).
CVSS v3.1
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel vulnerability CVE-2026-63987 concerns the ethtool coalesce feature where the ethlnl_update_profile() function iterates over the ETHTOOL_A_PROFILE_IRQ_MODERATION nested Netlink attributes using an index 'i' to write new profile data. The index 'i' is not properly bounded, allowing writes beyond the allocated buffer size, which is fixed at NET_DIM_PARAMS_NUM_PROFILES (5 entries). Since Netlink policies do not constrain the number of nested entries, a user-controlled Netlink message can cause out-of-bounds memory writes. This vulnerability has been resolved in the Linux kernel.
Potential Impact
The vulnerability allows a user to send a crafted Netlink message with more nested profile entries than the kernel expects, potentially causing out-of-bounds memory writes. This could lead to memory corruption, which might be exploitable for privilege escalation or denial of service. However, no known exploits in the wild have been reported.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel. Users and administrators should apply the official kernel updates that include this patch. Since this is a kernel-level vulnerability, updating to a patched kernel version is the recommended remediation. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor or Linux kernel advisory for the exact fixed versions and update accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-88qj-mcxj-4mfv
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-63987"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a5d27aa2a4a8d598912e214
Added to database: 07/19/2026, 19:38:18 UTC
Last enriched: 07/19/2026, 20:02:21 UTC
Last updated: 07/20/2026, 21:51:32 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.