{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-63926","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.021Z","datePublished":"2026-07-19T14:55:27.154Z","dateUpdated":"2026-08-05T12:37:21.277Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:37:21.277Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: sockmap: fix tail fragment offset in bpf_msg_push_data\n\nWhen bpf_msg_push_data() inserts data in the middle of a scatterlist\nentry, it splits the original entry into a left fragment and a right\nfragment.\n\nThe right fragment offset is page-local, but the code advances it with\n`start`, which is the message-global insertion point. For inserts into a\nnon-first SG entry, this over-advances the offset and leaves the split\nlayout inconsistent.\n\nAdvance the right fragment offset by the fragment-local delta,\n`start - offset`, which matches the length removed from the front of the\noriginal entry."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached through the BPF sk_msg/sockmap send path (sendmsg → tcp_bpf_send_verdict → sk_psock_msg_verdict → bpf_msg_push_data), which requires local syscalls and BPF setup; per kernel CNA guidance, BPF/sockmap issues are scored as Local rather than Network.\nAC:L - An attacker who can load a sk_msg BPF program fully controls the insertion offset and can reliably build multi-fragment scatterlist messages (e.g., via large sendmsg/sendfile) to hit the non-first-entry split path; a public PoC demonstrates deterministic triggering without races or external victim state.\nPR:N - While direct exploitation requires CAP_NET_ADMIN+CAP_BPF to load sockmap/sk_msg programs (obtainable as PR:L via user namespaces), the highest-impact reasonable scenario is an unauthenticated remote client triggering a pre-deployed internet-facing kTLS/sockmap proxy whose sk_msg BPF calls bpf_msg_push_data during outbound processing, requiring no privileges on the victim host.\nUI:N - Exploitation requires no victim user interaction beyond normal network I/O to a service that already runs sockmap/sk_msg BPF; the attacker does not need the victim to mount filesystems, open files, or take other deliberate actions.\nS:U - Impact is kernel heap memory corruption within the same kernel security authority (privilege escalation, memory disclosure, or crash), not a cross-boundary escape such as VM guest-to-host or IOMMU bypass.\nC:H - The incorrect rsge.offset over-advances the page-local offset for non-first scatterlist fragments, causing out-of-bounds reads when subsequent helpers (e.g., bpf_msg_pull_data via sg_virt/memcpy) or the TCP send path consume the corrupted entry; the public PoC shows a 32,752-byte OOB read/UAF.\nI:H - Scatterlist metadata corruption produces inconsistent length/offset pairs that can drive out-of-bounds kernel memory access and is a standard heap corruption primitive potentially weaponizable for arbitrary write or control-flow hijack, not merely a bounded data error.\nA:H - Corrupted scatterlist state can cause kernel oops/panic from out-of-bounds page access (as shown in the PoC KASAN trace) or destabilize subsequent sk_msg/TCP/kTLS transmit processing, resulting in denial of service."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/core/filter.c"],"versions":[{"version":"6fff607e2f14bd7c63c06c464a6f93b8efbabe28","lessThan":"f14609d8146707452e0822f3c8154674ce677251","status":"affected","versionType":"git"},{"version":"6fff607e2f14bd7c63c06c464a6f93b8efbabe28","lessThan":"d81b323af2dcee47573907ccb89c0df9b45cb2e2","status":"affected","versionType":"git"},{"version":"6fff607e2f14bd7c63c06c464a6f93b8efbabe28","lessThan":"aeb95146848d12206e1b2cfacd4f40e21ce81d94","status":"affected","versionType":"git"},{"version":"6fff607e2f14bd7c63c06c464a6f93b8efbabe28","lessThan":"96b72672ce849a1402730238e64d9b20bf06a96d","status":"affected","versionType":"git"},{"version":"6fff607e2f14bd7c63c06c464a6f93b8efbabe28","lessThan":"3075c21d2d76c0067f4a382765b43d6cc10470f1","status":"affected","versionType":"git"},{"version":"6fff607e2f14bd7c63c06c464a6f93b8efbabe28","lessThan":"5e19028667963fb371ebb00cecc2a473ef92056b","status":"affected","versionType":"git"},{"version":"6fff607e2f14bd7c63c06c464a6f93b8efbabe28","lessThan":"63f64a510c7917658ddf4d073ece73914ee25346","status":"affected","versionType":"git"},{"version":"6fff607e2f14bd7c63c06c464a6f93b8efbabe28","lessThan":"f72eed9b84fb771019a955908132410a9ba9ea3f","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/core/filter.c"],"versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","status":"unaffected","versionType":"semver"},{"version":"5.10.259","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.210","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"5.10.259"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"5.15.210"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.1.176"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.6.143"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.12.93"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"6.18.35"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"7.0.12"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f14609d8146707452e0822f3c8154674ce677251"},{"url":"https://git.kernel.org/stable/c/d81b323af2dcee47573907ccb89c0df9b45cb2e2"},{"url":"https://git.kernel.org/stable/c/aeb95146848d12206e1b2cfacd4f40e21ce81d94"},{"url":"https://git.kernel.org/stable/c/96b72672ce849a1402730238e64d9b20bf06a96d"},{"url":"https://git.kernel.org/stable/c/3075c21d2d76c0067f4a382765b43d6cc10470f1"},{"url":"https://git.kernel.org/stable/c/5e19028667963fb371ebb00cecc2a473ef92056b"},{"url":"https://git.kernel.org/stable/c/63f64a510c7917658ddf4d073ece73914ee25346"},{"url":"https://git.kernel.org/stable/c/f72eed9b84fb771019a955908132410a9ba9ea3f"}],"title":"bpf: sockmap: fix tail fragment offset in bpf_msg_push_data","x_generator":{"engine":"bippy-1.2.0"}}}}