๐Ÿ” CVE Alert

CVE-2026-63830

UNKNOWN 0.0

net: skmsg: preserve sg.copy across SG transforms

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net: skmsg: preserve sg.copy across SG transforms The sk_msg sg.copy bitmap is part of the scatterlist entry ownership state. A set bit tells sk_msg_compute_data_pointers() not to expose the entry through writable BPF ctx->data. This protects entries backed by pages that are not private to the sk_msg, such as splice-backed file page-cache pages. Several sk_msg transform paths move, copy, split, or compact msg->sg.data[] entries without moving the matching sg.copy bit. This can make an externally backed entry arrive at a new slot with a clear copy bit. A later SK_MSG verdict can then expose sg_virt(sge) as writable ctx->data and BPF stores can modify the original page cache. Keep sg.copy synchronized with sg.data[] whenever entries are transferred, shifted, split, or copied into a new sk_msg. Clear the bit when an entry is replaced by a newly allocated private page or freed. This covers the BPF pull/push/pop helpers, sk_msg_shift_left/right(), sk_msg_xfer(), and tls_split_open_record(), including the partial tail entry created during TLS open-record splitting.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
d3b18ad31f93d0b6bae105c679018a1ba7daa9ca < 9bb86d8184b37503816150c4a6ad3c17dfdbe827 d3b18ad31f93d0b6bae105c679018a1ba7daa9ca < 0eb4c16c4adb262763bda870a8ed38a1a9dec7ec d3b18ad31f93d0b6bae105c679018a1ba7daa9ca < d22cc92bc41290e5783a72375e0843d9435f6001 d3b18ad31f93d0b6bae105c679018a1ba7daa9ca < 1acdd14c0990dd1cd4b6534f00366d2e6dfce05f d3b18ad31f93d0b6bae105c679018a1ba7daa9ca < 21ed9540a8e1906dfcbc1bb82ba9b4de4fa4bd6d d3b18ad31f93d0b6bae105c679018a1ba7daa9ca < 406e8a651a7b854c41fecd5117bb282b3a6c2c6b
Linux / Linux
4.20

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/9bb86d8184b37503816150c4a6ad3c17dfdbe827 git.kernel.org: https://git.kernel.org/stable/c/0eb4c16c4adb262763bda870a8ed38a1a9dec7ec git.kernel.org: https://git.kernel.org/stable/c/d22cc92bc41290e5783a72375e0843d9435f6001 git.kernel.org: https://git.kernel.org/stable/c/1acdd14c0990dd1cd4b6534f00366d2e6dfce05f git.kernel.org: https://git.kernel.org/stable/c/21ed9540a8e1906dfcbc1bb82ba9b4de4fa4bd6d git.kernel.org: https://git.kernel.org/stable/c/406e8a651a7b854c41fecd5117bb282b3a6c2c6b