๐Ÿ” CVE Alert

CVE-2026-63952

UNKNOWN 0.0

memfd: deny writeable mappings when implying SEAL_WRITE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: memfd: deny writeable mappings when implying SEAL_WRITE When SEAL_EXEC is added, SEAL_WRITE is implied to make W^X. But the implied seal is set after the check that makes sure the memfd can not have any writable mappings. This means one can use SEAL_EXEC to apply SEAL_WRITE while having writeable mappings. This breaks the contract that SEAL_WRITE provides and can be used by an attacker to pass a memfd that appears to be write sealed but can still be modified arbitrarily. Fix this by adding the implied seals before the call for mapping_deny_writable() is done.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
c4f75bc8bd6b3d62665e1f5400c419540edb5601 < b3f4f82d1315f1439059a83d1c22c51a5b43d99e c4f75bc8bd6b3d62665e1f5400c419540edb5601 < 3be2a24f7f72ad7321ed6ad1715b956a4527bcf4 c4f75bc8bd6b3d62665e1f5400c419540edb5601 < 0995d1f79aed8ccbf62056189dd53fd19726ea08 c4f75bc8bd6b3d62665e1f5400c419540edb5601 < 555702282d4536a865dfffb1cd4f6028f196e7e8 c4f75bc8bd6b3d62665e1f5400c419540edb5601 < 3b041514cb6eae45869b020f743c14d983363222
Linux / Linux
6.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/b3f4f82d1315f1439059a83d1c22c51a5b43d99e git.kernel.org: https://git.kernel.org/stable/c/3be2a24f7f72ad7321ed6ad1715b956a4527bcf4 git.kernel.org: https://git.kernel.org/stable/c/0995d1f79aed8ccbf62056189dd53fd19726ea08 git.kernel.org: https://git.kernel.org/stable/c/555702282d4536a865dfffb1cd4f6028f196e7e8 git.kernel.org: https://git.kernel.org/stable/c/3b041514cb6eae45869b020f743c14d983363222