Executive brief
A vulnerability in the Linux kernel's networking component could allow a local attacker to bypass security protections and modify sensitive system memory. Specifically, it affects how the system handles data buffers used by network programs, potentially allowing unauthorized changes to the file system cache. This could lead to data corruption or unauthorized modification of files that should remain read-only.
Technical details
A vulnerability exists in the Linux kernel's sk_msg implementation where the sg.copy bitmap is not correctly preserved during scatterlist (SG) transformations such as move, copy, split, or compact operations. The sg.copy bit is a security mechanism that prevents sk_msg_compute_data_pointers() from exposing non-private pages (like splice-backed file page-cache pages) as writable to BPF programs. When this bit is lost during a transform, an externally backed entry may be incorrectly marked as writable. A local attacker with the ability to load SK_MSG BPF programs can exploit this to modify the original page cache, leading to data corruption or integrity violations. The fix ensures the sg.copy bit is synchronized during all relevant sk_msg operations, including BPF pull/push/pop helpers and TLS record splitting.
Affected products
- Linux Linux Kernel 4.20 to 6.13
Timeline
- 2026-06-10: disclosed: Vulnerability reported by Yiming Qian and Keenan Dong
- 2026-07-04: patched: Fix committed to stable kernel trees
- 2026-07-19: advisory: CVE-2026-63830 published
References
- https://git.kernel.org/stable/c/0eb4c16c4adb262763bda870a8ed38a1a9dec7ec
- https://git.kernel.org/stable/c/1acdd14c0990dd1cd4b6534f00366d2e6dfce05f
- https://git.kernel.org/stable/c/21ed9540a8e1906dfcbc1bb82ba9b4de4fa4bd6d
- https://git.kernel.org/stable/c/406e8a651a7b854c41fecd5117bb282b3a6c2c6b
- https://git.kernel.org/stable/c/9bb86d8184b37503816150c4a6ad3c17dfdbe827
- https://git.kernel.org/stable/c/d22cc92bc41290e5783a72375e0843d9435f6001