CVE-2026-63986: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure The goto err label leads to: genlmsg_cancel(skb, ehdr); return ret; If ethnl_tsinfo_prepare_dump() failed, it has not started a genlmsg. There's nothing to cancel, and passing an error pointer to genlmsg_cancel() would cause a crash.
Affected products
- Linux Linux Kernel: from 6.14, before 6.18.35 (fixed in 6.18.35); from 6.19, before 7.0.12 (fixed in 7.0.12); version 7.1 only
Published 2026-07-19. Last modified 2026-10-08.