Re: CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback

From: Siddh Raman Pant

Date: Fri Jul 31 2026 - 03:16:14 EST


On Fri, Jul 31 2026 at 11:09:18 +0530, gregkh@xxxxxxxxxxxxxxxxxxx
wrote:
> On Fri, Jul 31, 2026 at 05:14:32AM +0000, Siddh Raman Pant wrote:
> > On Thu, Jul 30 2026 at 18:19:43 +0530, gregkh@xxxxxxxxxxxxxxxxxxx
> > wrote:
> >
> > > > IIUC this is a defensive fix. Does it fix any reported problem for it
> > > > to be a CVE?
> > >
> > > As-is, it seems to fix a vulnerability. Do you think that is not the
> > > case, and if so, why?
> >
> > I meant it closes potential only right? Or is there any driver in-tree
> > which had a surprise?
>
> Personally, I do not know, but this is hardware-dependent, right?

It's a generic layer so it should not be.

But looking at the code yet again closely, it seems driver like qede
seems to return success on read failure which would leak information.

Sorry for the noise. It wasn't obvious at start 😅.

Thanks,
Siddh

Attachment: signature.asc
Description: This is a digitally signed message part