CVE-2026-64548 (GCVE-0-2026-64548)
Vulnerability from cvelistv5
Published
2026-07-27 20:10
Modified
2026-08-17 04:57
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
When the scatterlist ring is full or nearly full, bpf_msg_push_data()
enters a copy fallback path and computes copy + len for the page
allocation size. Since len comes from BPF with arg3_type = ARG_ANYTHING
and both are u32, a crafted len can wrap the sum to a small value,
causing an undersized allocation followed by an out-of-bounds memcpy.
BUG: unable to handle page fault for address: ffffed104089a402
Oops: Oops: 0000 [#1] SMP KASAN NOPTI
Call Trace:
__asan_memcpy (mm/kasan/shadow.c:105)
bpf_msg_push_data (net/core/filter.c:2852 net/core/filter.c:2788)
bpf_prog_9ed8b5711920a7d7+0x2e/0x36
sk_psock_msg_verdict (net/core/skmsg.c:934)
tcp_bpf_sendmsg (net/ipv4/tcp_bpf.c:421 net/ipv4/tcp_bpf.c:584)
__sys_sendto (net/socket.c:2206)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)
Add an overflow check before the allocation.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 Version: 6fff607e2f14bd7c63c06c464a6f93b8efbabe28 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/core/filter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "f1644c9508d24f50dd9e8ebe8d3ba86e0996d2f5",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "a12b1575f9feabd91695a9e9d004862f7195fa25",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "ff39d0e3b4feeb65ca43c453d7c75fdf872ded0d",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "888706a76286c547bd035432602571e8024b5305",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "db77b6bb6e6edb79b10b4efcce346eec5582d588",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "4e40056bb5c829f0423f0a6694a0477726d2147e",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "bd004716ba75fed6d185795c85cdc92540ebeaab",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
},
{
"lessThan": "0c0a8ed85349dae298712d79cb276acfeb794d82",
"status": "affected",
"version": "6fff607e2f14bd7c63c06c464a6f93b8efbabe28",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/core/filter.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()\n\nWhen the scatterlist ring is full or nearly full, bpf_msg_push_data()\nenters a copy fallback path and computes copy + len for the page\nallocation size. Since len comes from BPF with arg3_type = ARG_ANYTHING\nand both are u32, a crafted len can wrap the sum to a small value,\ncausing an undersized allocation followed by an out-of-bounds memcpy.\n\n BUG: unable to handle page fault for address: ffffed104089a402\n Oops: Oops: 0000 [#1] SMP KASAN NOPTI\n Call Trace:\n __asan_memcpy (mm/kasan/shadow.c:105)\n bpf_msg_push_data (net/core/filter.c:2852 net/core/filter.c:2788)\n bpf_prog_9ed8b5711920a7d7+0x2e/0x36\n sk_psock_msg_verdict (net/core/skmsg.c:934)\n tcp_bpf_sendmsg (net/ipv4/tcp_bpf.c:421 net/ipv4/tcp_bpf.c:584)\n __sys_sendto (net/socket.c:2206)\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n\nAdd an overflow check before the allocation."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable helper only runs from the sk_msg egress verdict path, reached via a local `sendmsg()`/`sendto()` syscall on a sockmap- or kTLS-attached socket (`tcp_bpf_sendmsg` \u2192 `sk_psock_msg_verdict`, `tls_sw_sendmsg`), as shown in the reported call trace. There is no remote-peer input path into `bpf_msg_push_data()`.\nAC:L - Both trigger conditions are fully attacker-controlled and deterministic: the copy-fallback path is forced by sending \u2265 MAX_SKB_FRAGS*PAGE_SIZE bytes in one sendmsg to fill the SG ring, and the wrapping `len` is a constant chosen by the sk_msg program. No race, timing window, or uncontrolled memory state is involved.\nPR:N - The act that triggers the corruption \u2014 `sendmsg()` on a socket already in the sockmap \u2014 requires no privileges whatsoever, and the same helper\u0027s prior flaw (CVE-2026-63926) was scored PR:N on this basis. `ARG_ANYTHING` means the verifier enforces no bound, so a deployed L7-proxy sk_msg program that derives `len` from message content (e.g. a signed `want - have` underflowing to a huge u32) hands the wrapping value to the kernel without any attacker privilege; where program authorship is needed, CAP_BPF+CAP_NET_ADMIN is delegable to unprivileged container users via a bpffs BPF token.\nUI:N - Exploitation is entirely driven by the attacker\u0027s own socket writes and BPF program; no victim action, mount, or file access is required.\nS:U - The undersized allocation and out-of-bounds write corrupt kernel memory within the same security authority as the vulnerable code. No VM, IOMMU, or hypervisor boundary is crossed.\nC:H - The wild-offset write plus the corrupted `sg.size`/element-length/`data_end` state (huge `len` added to `sg.size` while `sg_set_page()` records the wrapped length) lets adjacent kernel memory be exposed to the BPF program and pushed out on the socket, and the write primitive is readily convertible into an arbitrary kernel read.\nI:H - `memcpy(raw + front + len, from, back)` writes up to a full SG element of attacker-supplied payload roughly 4 GiB past a single-page allocation, with the offset tunable over a ~4 MiB window and the source page groomable \u2014 an attacker-controlled write into the direct map, sufficient for control-flow hijack and privilege escalation.\nA:H - The reported reproducer is an unrecoverable oops (\"unable to handle page fault for address: ffffed104089a402\") when the wild pointer hits unmapped direct-map space, and the ~4 GiB `sk_mem_charge()`/`sg.size` accounting corruption further destabilises the socket and allocator."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:57:25.465Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/f1644c9508d24f50dd9e8ebe8d3ba86e0996d2f5"
},
{
"url": "https://git.kernel.org/stable/c/a12b1575f9feabd91695a9e9d004862f7195fa25"
},
{
"url": "https://git.kernel.org/stable/c/ff39d0e3b4feeb65ca43c453d7c75fdf872ded0d"
},
{
"url": "https://git.kernel.org/stable/c/888706a76286c547bd035432602571e8024b5305"
},
{
"url": "https://git.kernel.org/stable/c/db77b6bb6e6edb79b10b4efcce346eec5582d588"
},
{
"url": "https://git.kernel.org/stable/c/4e40056bb5c829f0423f0a6694a0477726d2147e"
},
{
"url": "https://git.kernel.org/stable/c/bd004716ba75fed6d185795c85cdc92540ebeaab"
},
{
"url": "https://git.kernel.org/stable/c/0c0a8ed85349dae298712d79cb276acfeb794d82"
}
],
"title": "bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64548",
"datePublished": "2026-07-27T20:10:38.355Z",
"dateReserved": "2026-07-19T15:36:31.795Z",
"dateUpdated": "2026-08-17T04:57:25.465Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…