๐Ÿ” CVE Alert

CVE-2026-63890

UNKNOWN 0.0

scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker drivers/scsi/fcoe/fcoe_ctlr.c::fcoe_ctlr_recv_clr_vlink() advanced the descriptor cursor by an attacker-supplied fip_dlen without ever requiring dlen >= sizeof(struct fip_desc) in the default branch. The named descriptor cases (FIP_DT_MAC, FIP_DT_NAME, FIP_DT_VN_ID) checked their per-type minimum lengths, but a FIP_DT_NON_CRITICAL descriptor (fip_dtype >= 128, which the standard requires receivers to silently ignore) skipped that check entirely. An unauthenticated L2 peer on the FCoE control VLAN could hang fcoe_ctlr_recv_work on an fcoe, qedf, or bnx2fc initiator indefinitely by emitting one FIP CVL frame whose single descriptor had fip_dtype == FIP_DT_NON_CRITICAL and fip_dlen == 0: the cursor advanced zero bytes per iteration and the loop condition rlen >= sizeof(*desc) stayed true forever, blocking every subsequent FIP frame on that controller. Tighten the outer dlen guard to also reject dlen < sizeof(struct fip_desc), so a malformed descriptor whose length cannot even cover the descriptor header is rejected before the switch. This is the same lower-bound the named cases already apply and is the minimum scope that closes the loop.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
97c8389d54b9665c38105ea72a428a44b97ff2f6 < d179949d2175d2857d1c3a275a22bea58bcc5d36 97c8389d54b9665c38105ea72a428a44b97ff2f6 < fda976f7390bb5d1e9b84ef11ebb17323038e0c6 97c8389d54b9665c38105ea72a428a44b97ff2f6 < 80a0cd307205236ca28aa49bc553f58edcb9bf3a 97c8389d54b9665c38105ea72a428a44b97ff2f6 < 0e3c6e5a8fc15a74dfb1e0c1df9f1da73600a81a 97c8389d54b9665c38105ea72a428a44b97ff2f6 < 549859a1131052b07dff11a448e9f3221a40f260 97c8389d54b9665c38105ea72a428a44b97ff2f6 < 14dd80a20a72ce334adcc2d67402360527065948 97c8389d54b9665c38105ea72a428a44b97ff2f6 < d537d29d51c8b808469e5adacf3e5a0092700738 97c8389d54b9665c38105ea72a428a44b97ff2f6 < 9eed1bd59937e6828b00d2f2dfef631d964f3636
Linux / Linux
2.6.30

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/d179949d2175d2857d1c3a275a22bea58bcc5d36 git.kernel.org: https://git.kernel.org/stable/c/fda976f7390bb5d1e9b84ef11ebb17323038e0c6 git.kernel.org: https://git.kernel.org/stable/c/80a0cd307205236ca28aa49bc553f58edcb9bf3a git.kernel.org: https://git.kernel.org/stable/c/0e3c6e5a8fc15a74dfb1e0c1df9f1da73600a81a git.kernel.org: https://git.kernel.org/stable/c/549859a1131052b07dff11a448e9f3221a40f260 git.kernel.org: https://git.kernel.org/stable/c/14dd80a20a72ce334adcc2d67402360527065948 git.kernel.org: https://git.kernel.org/stable/c/d537d29d51c8b808469e5adacf3e5a0092700738 git.kernel.org: https://git.kernel.org/stable/c/9eed1bd59937e6828b00d2f2dfef631d964f3636