Junglewise Threat Intelligence

CVE-2026-63809: Linux Kernel memory corruption in BPF sysctl handling

CVE-2026-63809 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's BPF subsystem that could lead to system instability or crashes. The issue occurs when the system handles certain configuration changes (sysctl writes) within a cgroup, where memory is incorrectly freed using an incompatible function. This could allow a local user to trigger a kernel memory corruption, potentially leading to a denial-of-service (system crash).

Technical details

A memory management vulnerability exists in the Linux kernel's BPF subsystem within the `__cgroup_bpf_run_filter_sysctl` function. The `proc_sys_call_handler()` allocates a temporary buffer using `kvzalloc()`, which may utilize `vmalloc()` for larger allocations. However, the code incorrectly attempts to release this buffer using `kfree()` when it is replaced. Because `kfree()` cannot safely handle `vmalloc` addresses, this mismatch results in a kernel oops and memory corruption. An attacker with local access could trigger this by writing to specific sysctl entries (e.g., /proc/sys/kernel/domainname) from within a monitored cgroup. The issue has been resolved by switching to `kvfree()`, which correctly handles both slab and vmalloc allocations.

Affected products

  • Linux Linux Kernel v6.13-rc1 to v7.1-rc5

Timeline

  • 2026-06-03: disclosed: Patch submitted by Dawei Feng
  • 2026-07-04: patched: Merged into stable branches by Greg Kroah-Hartman
  • 2026-07-19: advisory: CVE-2026-63809 published

References

Related threats