Possible buffer overflow in portcfgfportbuffers in Brocade Fabric OS
Description
In Brocade Fabric OS before v9.2.0a, a local authenticated privileged user can trigger a buffer overflow condition, leading to a kernel panic with large input to buffers in the portcfgfportbuffers command.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A buffer overflow in Brocade Fabric OS's portcfgfportbuffers command allows a local privileged user to cause a kernel panic.
Vulnerability
A buffer overflow vulnerability exists in the portcfgfportbuffers command of Brocade Fabric OS. A local authenticated privileged user can supply large input to buffers, triggering a buffer overflow condition that leads to a kernel panic. All versions of Brocade Fabric OS prior to the fixed releases are affected, including versions before v9.2.0a [1].
Exploitation
An attacker must have local authenticated privileged access to a Brocade switch running an affected version of Fabric OS. The attacker then executes the portcfgfportbuffers command with oversized input, causing a buffer overflow that results in a kernel panic [1]. No user interaction beyond the attacker's own actions is required.
Impact
Successful exploitation causes a kernel panic, resulting in a denial of service (system crash). The vulnerability does not appear to allow code execution or privilege escalation; the primary impact is on availability [1].
Mitigation
Brocade has released fixed versions: Fabric OS v9.2.0a, v9.1.1d, and v8.2.3e [1]. Users should upgrade to one of these versions or later. No workarounds are documented. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <9.2.0a
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.