Re: CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback
From: gregkh@xxxxxxxxxxxxxxxxxxx
Date: Fri Jul 31 2026 - 01:39:38 EST
On Fri, Jul 31, 2026 at 05:14:32AM +0000, Siddh Raman Pant wrote:
> On Thu, Jul 30 2026 at 18:19:43 +0530, gregkh@xxxxxxxxxxxxxxxxxxx
> wrote:
>
> > > IIUC this is a defensive fix. Does it fix any reported problem for it
> > > to be a CVE?
> >
> > As-is, it seems to fix a vulnerability. Do you think that is not the
> > case, and if so, why?
>
> I meant it closes potential only right? Or is there any driver in-tree
> which had a surprise?
Personally, I do not know, but this is hardware-dependent, right?