CVE-2026-63830 (GCVE-0-2026-63830)
Vulnerability from cvelistv5
Published
2026-07-19 12:02
Modified
2026-08-17 04:51
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: skmsg: preserve sg.copy across SG transforms
The sk_msg sg.copy bitmap is part of the scatterlist entry ownership
state. A set bit tells sk_msg_compute_data_pointers() not to expose the
entry through writable BPF ctx->data. This protects entries backed by
pages that are not private to the sk_msg, such as splice-backed file
page-cache pages.
Several sk_msg transform paths move, copy, split, or compact
msg->sg.data[] entries without moving the matching sg.copy bit. This can
make an externally backed entry arrive at a new slot with a clear copy
bit. A later SK_MSG verdict can then expose sg_virt(sge) as writable
ctx->data and BPF stores can modify the original page cache.
Keep sg.copy synchronized with sg.data[] whenever entries are
transferred, shifted, split, or copied into a new sk_msg. Clear the bit
when an entry is replaced by a newly allocated private page or freed.
This covers the BPF pull/push/pop helpers, sk_msg_shift_left/right(),
sk_msg_xfer(), and tls_split_open_record(), including the partial tail
entry created during TLS open-record splitting.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: d3b18ad31f93d0b6bae105c679018a1ba7daa9ca Version: d3b18ad31f93d0b6bae105c679018a1ba7daa9ca Version: d3b18ad31f93d0b6bae105c679018a1ba7daa9ca Version: d3b18ad31f93d0b6bae105c679018a1ba7daa9ca Version: d3b18ad31f93d0b6bae105c679018a1ba7daa9ca Version: d3b18ad31f93d0b6bae105c679018a1ba7daa9ca Version: d3b18ad31f93d0b6bae105c679018a1ba7daa9ca Version: d3b18ad31f93d0b6bae105c679018a1ba7daa9ca |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/skmsg.h",
"net/core/filter.c",
"net/core/skmsg.c",
"net/tls/tls_sw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f126eed589eec6f201405abbc398844042ef6d57",
"status": "affected",
"version": "d3b18ad31f93d0b6bae105c679018a1ba7daa9ca",
"versionType": "git"
},
{
"lessThan": "31a110642b5fb5e61940cbcfb503445ac4f28017",
"status": "affected",
"version": "d3b18ad31f93d0b6bae105c679018a1ba7daa9ca",
"versionType": "git"
},
{
"lessThan": "9bb86d8184b37503816150c4a6ad3c17dfdbe827",
"status": "affected",
"version": "d3b18ad31f93d0b6bae105c679018a1ba7daa9ca",
"versionType": "git"
},
{
"lessThan": "0eb4c16c4adb262763bda870a8ed38a1a9dec7ec",
"status": "affected",
"version": "d3b18ad31f93d0b6bae105c679018a1ba7daa9ca",
"versionType": "git"
},
{
"lessThan": "d22cc92bc41290e5783a72375e0843d9435f6001",
"status": "affected",
"version": "d3b18ad31f93d0b6bae105c679018a1ba7daa9ca",
"versionType": "git"
},
{
"lessThan": "1acdd14c0990dd1cd4b6534f00366d2e6dfce05f",
"status": "affected",
"version": "d3b18ad31f93d0b6bae105c679018a1ba7daa9ca",
"versionType": "git"
},
{
"lessThan": "21ed9540a8e1906dfcbc1bb82ba9b4de4fa4bd6d",
"status": "affected",
"version": "d3b18ad31f93d0b6bae105c679018a1ba7daa9ca",
"versionType": "git"
},
{
"lessThan": "406e8a651a7b854c41fecd5117bb282b3a6c2c6b",
"status": "affected",
"version": "d3b18ad31f93d0b6bae105c679018a1ba7daa9ca",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/skmsg.h",
"net/core/filter.c",
"net/core/skmsg.c",
"net/tls/tls_sw.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.177",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.144",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.95",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.38",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.177",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.144",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.95",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.38",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.3",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skmsg: preserve sg.copy across SG transforms\n\nThe sk_msg sg.copy bitmap is part of the scatterlist entry ownership\nstate. A set bit tells sk_msg_compute_data_pointers() not to expose the\nentry through writable BPF ctx-\u003edata. This protects entries backed by\npages that are not private to the sk_msg, such as splice-backed file\npage-cache pages.\n\nSeveral sk_msg transform paths move, copy, split, or compact\nmsg-\u003esg.data[] entries without moving the matching sg.copy bit. This can\nmake an externally backed entry arrive at a new slot with a clear copy\nbit. A later SK_MSG verdict can then expose sg_virt(sge) as writable\nctx-\u003edata and BPF stores can modify the original page cache.\n\nKeep sg.copy synchronized with sg.data[] whenever entries are\ntransferred, shifted, split, or copied into a new sk_msg. Clear the bit\nwhen an entry is replaced by a newly allocated private page or freed.\nThis covers the BPF pull/push/pop helpers, sk_msg_shift_left/right(),\nsk_msg_xfer(), and tls_split_open_record(), including the partial tail\nentry created during TLS open-record splitting."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.4,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - The bug is exercised on the kTLS/TCP send path when splice-backed page-cache pages in an sk_msg are processed by an SK_MSG BPF verdict on network sockets; a remote TLS peer can trigger this on internet-facing servers (HTTPS, service-mesh edge nodes) that serve file-backed responses via splice/sendfile.\nAC:L - The attacker controls the traffic patterns, message sizes, and splice-backed data needed to hit the desynchronized transform paths (bpf_msg_push/pop/pull, sk_msg shift/xfer, tls_split_open_record); no race against unrelated system state is required.\nPR:N - On production kTLS servers with an attached SK_MSG BPF program (common in Cilium/Cloudflare-class deployments), an unauthenticated remote peer can trigger the faulty transforms without any credentials on the victim; a fully local exploit via user-namespace CAP_NET_ADMIN is also possible but is not the highest-severity case.\nUI:N - Exploitation requires only network traffic to a vulnerable server (or local socket I/O); no victim user action such as opening a file or mounting a filesystem is needed beyond normal server operation.\nS:U - Impact remains within the kernel\u0027s security authority (page-cache corruption via the network/BPF stack); it does not cross a VM-hypervisor or IOMMU boundary even though corrupted cache pages may affect other processes.\nC:H - Exposing splice-backed page-cache pages as writable BPF ctx-\u003edata gives the attacker a kernel memory write primitive over shared file cache pages, which can be leveraged to read or infer sensitive file contents served from or mapped through the corrupted pages.\nI:H - The commit explicitly states BPF stores through the incorrectly writable ctx-\u003edata can modify the original page cache, constituting arbitrary integrity corruption of file-backed data beyond the socket buffer.\nA:L - While the primary impact is data corruption rather than a kernel oops, corrupting shared page-cache pages of files actively served to other clients can cause sustained service disruption and repeated application-level failures; when uncertain, availability impact above None is appropriate."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:51:39.075Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f126eed589eec6f201405abbc398844042ef6d57"
},
{
"url": "https://git.kernel.org/stable/c/31a110642b5fb5e61940cbcfb503445ac4f28017"
},
{
"url": "https://git.kernel.org/stable/c/9bb86d8184b37503816150c4a6ad3c17dfdbe827"
},
{
"url": "https://git.kernel.org/stable/c/0eb4c16c4adb262763bda870a8ed38a1a9dec7ec"
},
{
"url": "https://git.kernel.org/stable/c/d22cc92bc41290e5783a72375e0843d9435f6001"
},
{
"url": "https://git.kernel.org/stable/c/1acdd14c0990dd1cd4b6534f00366d2e6dfce05f"
},
{
"url": "https://git.kernel.org/stable/c/21ed9540a8e1906dfcbc1bb82ba9b4de4fa4bd6d"
},
{
"url": "https://git.kernel.org/stable/c/406e8a651a7b854c41fecd5117bb282b3a6c2c6b"
}
],
"title": "net: skmsg: preserve sg.copy across SG transforms",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-63830",
"datePublished": "2026-07-19T12:02:23.741Z",
"dateReserved": "2026-07-19T07:54:57.014Z",
"dateUpdated": "2026-08-17T04:51:39.075Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…