In the Linux kernel, the following vulnerability has been resolved:
ethtool: module: call ethnl_ops_complete() on module flash errors
When validate() fails we are skipping over ethnl_ops_complete() even tho we already called ethnl_ops_begin().
A fix is available — apply it.
In the Linux kernel, the following vulnerability has been resolved:
ethtool: module: call ethnl_ops_complete() on module flash errors
When validate() fails we are skipping over ethnl_ops_complete() even tho we already called ethnl_ops_begin().
July 19, 2026
July 30, 2026
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | linux-tools-azure-fde-7.0 (7.0.0-1009.9) @ resolute | 2026-08-30 | ubuntu |
| ubuntu | linux-tools-raspi-realtime-7.0 (7.0.0-1015.15) @ resolute | 2026-08-30 | ubuntu |
| ubuntu | linux-tools-oracle-7.0 (7.0.0-1008.8) @ resolute | 2026-08-30 | ubuntu |
| ubuntu | linux-tools-nvidia-hwe-24.04-edge (7.0.0-1016.16) @ resolute | 2026-08-30 | ubuntu |
| ubuntu | linux-tools-nvidia-hwe-26.04 (7.0.0-2016.16) @ resolute | 2026-08-30 | ubuntu |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| linux | 6.12.100-1 ... 7.2~rc5-1~exp1 (160 versions) | — | — |
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| linux | 6.12.100-1 ... 7.0.9-1~bpo13+1 (138 versions) | 7.0.12-1 | — |
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-63998
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.