Description
A stack-based buffer overflow vulnerability exists in the diagnostic execution utility of Brocade Fabric OS versions before 10.0.1. When processing command arguments for diagnostic operations, the utility tokenizes user-supplied input into an internal argument array without enforcing boundary checks on the maximum array capacity. An authenticated user with administrative access can exploit this vulnerability by supplying a crafted diagnostic command string containing an excessive number of tokenized arguments. This leads to a memory overwrite resulting in a denial of service (process crash).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Security update is provided in Brocade Fabric OS 10.0.1
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 08 Oct 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow vulnerability exists in the diagnostic execution utility of Brocade Fabric OS versions before 10.0.1. When processing command arguments for diagnostic operations, the utility tokenizes user-supplied input into an internal argument array without enforcing boundary checks on the maximum array capacity. An authenticated user with administrative access can exploit this vulnerability by supplying a crafted diagnostic command string containing an excessive number of tokenized arguments. This leads to a memory overwrite resulting in a denial of service (process crash). | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T03:00:54.306Z
Reserved: 2026-09-08T22:51:12.106Z
Link: CVE-2026-87668
No data.
Status : Received
Published: 2026-10-08T03:16:36.100
Modified: 2026-10-08T03:16:36.100
Link: CVE-2026-87668
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-121
Stack-based Buffer Overflow