A stack-based buffer overflow vulnerability exists in the diagnostic execution utility of Brocade Fabric OS versions before 10.0.1. When processing command arguments for diagnostic operations, the utility tokenizes user-supplied input into an internal argument array without enforcing boundary checks on the maximum array capacity. An authenticated user with administrative access can exploit this vulnerability by supplying a crafted diagnostic command string containing an excessive number of tokenized arguments. This leads to a memory overwrite resulting in a denial of service (process crash).
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Security update is provided in Brocade Fabric OS 10.0.1
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stack-Based Buffer Overflow in Brocade Fabric OS Diagnostic Utility Causes Denial of Service | |
| First Time appeared |
Brocade
Brocade fabric Os |
|
| Vendors & Products |
Brocade
Brocade fabric Os |
Thu, 08 Oct 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow vulnerability exists in the diagnostic execution utility of Brocade Fabric OS versions before 10.0.1. When processing command arguments for diagnostic operations, the utility tokenizes user-supplied input into an internal argument array without enforcing boundary checks on the maximum array capacity. An authenticated user with administrative access can exploit this vulnerability by supplying a crafted diagnostic command string containing an excessive number of tokenized arguments. This leads to a memory overwrite resulting in a denial of service (process crash). | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: brocade
Published:
Updated: 2026-10-08T03:00:54.306Z
Reserved: 2026-09-08T22:51:12.106Z
Link: CVE-2026-87668
No data.
Status : Received
Published: 2026-10-08T03:16:36.100
Modified: 2026-10-08T03:16:36.100
Link: CVE-2026-87668
No data.
OpenCVE Enrichment
Updated: 2026-10-08T04:30:13Z
Weaknesses