CVE-2026-63890

Description

A flaw was found in the Linux kernel's Fibre Channel over Ethernet (FCoE) module. An unauthenticated attacker on the same Layer 2 (L2) network segment could send a specially crafted FCoE Initialization Protocol (FIP) frame with a malformed descriptor. This could lead to an infinite loop, causing a denial of service (DoS) by blocking all further FIP communication on the affected controller.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Amplification

An infinite loop will cause unexpected consumption of resources, such as CPU cycles or memory. The software's operation may slow down, or cause a long time to respond.

Frequently Asked Questions

Want to get errata notifications? Sign up here.