A newly published Linux kernel vulnerability in the macb Ethernet driver is a reminder that even small accounting mistakes in networking code can become memory-safety bugs. CVE-2026-31494 covers an out-of-bounds write in gem_get_ethtool_stats, where the driver copies statistics for the maximum...
A small, targeted fix in the Linux macb network driver — described in the CVE record as "net: macb: fix unregister_netdev call order in macb_remove" (CVE‑2025‑39805) — has prompted Microsoft to publish a product‑scoped attestation that Azure Linux includes the affected open‑source component and...