Re: CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback
From: Siddh Raman Pant
Date: Fri Jul 31 2026 - 03:16:14 EST
On Fri, Jul 31 2026 at 11:09:18 +0530, gregkh@xxxxxxxxxxxxxxxxxxx
wrote:
> On Fri, Jul 31, 2026 at 05:14:32AM +0000, Siddh Raman Pant wrote:
> > On Thu, Jul 30 2026 at 18:19:43 +0530, gregkh@xxxxxxxxxxxxxxxxxxx
> > wrote:
> >
> > > > IIUC this is a defensive fix. Does it fix any reported problem for it
> > > > to be a CVE?
> > >
> > > As-is, it seems to fix a vulnerability. Do you think that is not the
> > > case, and if so, why?
> >
> > I meant it closes potential only right? Or is there any driver in-tree
> > which had a surprise?
>
> Personally, I do not know, but this is hardware-dependent, right?
It's a generic layer so it should not be.
But looking at the code yet again closely, it seems driver like qede
seems to return success on read failure which would leak information.
Sorry for the noise. It wasn't obvious at start 😅.
Thanks,
Siddh
Attachment:
signature.asc
Description: This is a digitally signed message part