CVE-2026-63997EPSS p5.5%
CVE-2026-63997CVE-2026-63997
Description
In the Linux kernel, the following vulnerability has been resolved:
ethtool: module: avoid leaking a netdev ref on module flash errors
module_flash_fw_schedule() is missing undo for setting
the "in_progress" flag and taking the netdev reference.
Delay taking these, the device can't disappear while
we are holding rtnl_lock.
Scoring
| EPSS | 0.17% probability of exploitation · percentile 5.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-30 |