{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-63952","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.023Z","datePublished":"2026-07-19T14:55:44.809Z","dateUpdated":"2026-08-05T12:37:37.398Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:37:37.398Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmemfd: deny writeable mappings when implying SEAL_WRITE\n\nWhen SEAL_EXEC is added, SEAL_WRITE is implied to make W^X.  But the\nimplied seal is set after the check that makes sure the memfd can not have\nany writable mappings.  This means one can use SEAL_EXEC to apply\nSEAL_WRITE while having writeable mappings.\n\nThis breaks the contract that SEAL_WRITE provides and can be used by an\nattacker to pass a memfd that appears to be write sealed but can still be\nmodified arbitrarily.\n\nFix this by adding the implied seals before the call for\nmapping_deny_writable() is done."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires local syscalls (memfd_create, mmap, fcntl) with no network-facing code path; the vulnerable logic is reached only through the local fcntl(F_ADD_SEALS) interface on a memfd file descriptor.\nAC:L - The attack is a reliable, deterministic syscall sequence (create executable memfd, establish a writable MAP_SHARED mapping, then apply F_SEAL_EXEC) with no race or attacker-uncontrollable conditions.\nPR:L - Any unprivileged local user can invoke memfd_create, mmap, and fcntl without capabilities; these interfaces are available inside unprivileged user namespaces with no real-root requirement.\nUI:N - Exploitation does not require a human victim action; in the highest-impact scenario a sandboxed process programmatically passes the sealed-appearing memfd to a trusting peer via IPC (e.g., SCM_RIGHTS) without user interaction.\nS:C - The bug breaks the memfd seal security contract designed for mutually untrusted parties, allowing a malicious local peer to deceive a separate process that relies on F_SEAL_WRITE immutability, crossing the inter-process trust boundary (sandbox/W^X enforcement).\nC:H - Bypassing write-seal/W^X guarantees enables arbitrary modification of executable memfd contents presented as immutable, which can be leveraged for arbitrary code execution in a trusting victim process and thereby full read of that process's memory.\nI:H - The vulnerability allows arbitrary modification of memory that is advertised as write-sealed (F_SEAL_WRITE), defeating the kernel's immutability guarantee and enabling W^X bypass and code injection into trusted execution contexts.\nA:N - The flaw is a logic error in seal enforcement that does not cause kernel crashes, panics, hangs, or denial of service; exploitation maintains availability while subverting integrity guarantees."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["mm/memfd.c"],"versions":[{"version":"c4f75bc8bd6b3d62665e1f5400c419540edb5601","lessThan":"b3f4f82d1315f1439059a83d1c22c51a5b43d99e","status":"affected","versionType":"git"},{"version":"c4f75bc8bd6b3d62665e1f5400c419540edb5601","lessThan":"3be2a24f7f72ad7321ed6ad1715b956a4527bcf4","status":"affected","versionType":"git"},{"version":"c4f75bc8bd6b3d62665e1f5400c419540edb5601","lessThan":"0995d1f79aed8ccbf62056189dd53fd19726ea08","status":"affected","versionType":"git"},{"version":"c4f75bc8bd6b3d62665e1f5400c419540edb5601","lessThan":"555702282d4536a865dfffb1cd4f6028f196e7e8","status":"affected","versionType":"git"},{"version":"c4f75bc8bd6b3d62665e1f5400c419540edb5601","lessThan":"3b041514cb6eae45869b020f743c14d983363222","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["mm/memfd.c"],"versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","status":"unaffected","versionType":"semver"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.93","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.35","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"6.6.143"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"6.12.93"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"6.18.35"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"7.0.12"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b3f4f82d1315f1439059a83d1c22c51a5b43d99e"},{"url":"https://git.kernel.org/stable/c/3be2a24f7f72ad7321ed6ad1715b956a4527bcf4"},{"url":"https://git.kernel.org/stable/c/0995d1f79aed8ccbf62056189dd53fd19726ea08"},{"url":"https://git.kernel.org/stable/c/555702282d4536a865dfffb1cd4f6028f196e7e8"},{"url":"https://git.kernel.org/stable/c/3b041514cb6eae45869b020f743c14d983363222"}],"title":"memfd: deny writeable mappings when implying SEAL_WRITE","x_generator":{"engine":"bippy-1.2.0"}}}}