Junglewise Threat Intelligence

CVE-2026-63799: Linux Kernel out-of-bounds write in sched/mmcid

CVE-2026-63799 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's process scheduler could allow for minor memory corruption. This occurs during specific process management tasks (like starting or ending programs) when the system is managing CPU identifiers. While the corruption is limited to a single bit of data at a fixed location, it could potentially lead to system instability or unpredictable behavior.

Technical details

An out-of-bounds (OOB) write vulnerability exists in the Linux kernel scheduler's mm_cid (memory management concurrency ID) implementation. In mm_cid_fixup_cpus_to_tasks(), the code fails to properly validate the MM_CID_UNSET sentinel value before applying a transition bit. This results in a deterministic OOB bit-clear operation via clear_bit() at a fixed offset (approximately 256 MiB) past the intended bitmap in the mm_struct. The issue is triggered in per-CPU CID mode during the window between a fork/exec and the task's first schedule-in. While the write is not attacker-controlled in terms of address or value, it corrupts one bit of kernel memory, which was detected as a use-after-free by KASAN. Patches have been released in the stable kernel tree.

Affected products

  • Linux Linux Kernel fbd0e71dc370af73f6b316e4de9eed273dd90340 to 8d32856fb72ba976d9c87ba405fd17e80419934c

Timeline

  • 2026-06-16: disclosed: Initial patch submission by Rik van Riel
  • 2026-07-04: patched: Patch committed to stable tree by Greg Kroah-Hartman
  • 2026-07-19: advisory: CVE-2026-63799 published

References