Executive brief
A vulnerability was identified in the Linux kernel's BPF subsystem that could lead to system instability or crashes. The issue occurs when the system handles certain configuration changes (sysctl writes) within a cgroup, where memory is incorrectly freed using an incompatible function. This could allow a local user to trigger a kernel memory corruption, potentially leading to a denial-of-service (system crash).
Technical details
A memory management vulnerability exists in the Linux kernel's BPF subsystem within the `__cgroup_bpf_run_filter_sysctl` function. The `proc_sys_call_handler()` allocates a temporary buffer using `kvzalloc()`, which may utilize `vmalloc()` for larger allocations. However, the code incorrectly attempts to release this buffer using `kfree()` when it is replaced. Because `kfree()` cannot safely handle `vmalloc` addresses, this mismatch results in a kernel oops and memory corruption. An attacker with local access could trigger this by writing to specific sysctl entries (e.g., /proc/sys/kernel/domainname) from within a monitored cgroup. The issue has been resolved by switching to `kvfree()`, which correctly handles both slab and vmalloc allocations.
Affected products
- Linux Linux Kernel v6.13-rc1 to v7.1-rc5
Timeline
- 2026-06-03: disclosed: Patch submitted by Dawei Feng
- 2026-07-04: patched: Merged into stable branches by Greg Kroah-Hartman
- 2026-07-19: advisory: CVE-2026-63809 published
References
- https://git.kernel.org/stable/c/4c21b5927d4364bfe7365f2700da5fea0ed0d004
- https://git.kernel.org/stable/c/65bd0c0afb0e1bf3287458e342429b069624f7d4
- https://git.kernel.org/stable/c/70df4de46577fab5e25418f014583155a147c902
- https://git.kernel.org/stable/c/77355ef7a9f6b0d2bdf65be3b37f2c1f365e20d2
- https://git.kernel.org/stable/c/81fc9a13acae99966232f0e055eb2e445263b89a
- https://git.kernel.org/stable/c/838fe9c28121777c59a9406710a68fcf77bb8017
- https://git.kernel.org/stable/c/d0a81ed5ff5d0f9c3f63a4f9e5a4642c363ecd3e