HIGH Introduced in 4.20
bpf sockmap PushData OOB
CVE-2026-63926
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI6.7MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data When bpf_msg_push_data() inserts data in the middle of a scatterlist entry, it splits the original entry into a left fragment and a right fragment. The right fragment offset is page-local, but the code advances it with `start`, which is the message-global insertion point. For inserts into a non-first SG entry, this over-advances the offset and leaves the split layout inconsistent. Advance the right fragment offset by the fragment-local delta, `start - offset`, which matches the length removed from the front of the original entry.
02KernelScan AI Analysis
Risk summary
A local user with access to BPF sockmap programs can trigger an incorrect scatterlist fragment offset calculation in bpf_msg_push_data(), causing memory corruption in kernel heap structures. Successful exploitation could allow privilege escalation or kernel code execution, though heap grooming is required to reliably exploit the corruption.
Vulnerability analysis
The bug is in bpf_msg_push_data() in net/core/filter.c. When inserting data into the middle of a scatterlist entry that is not the first entry in the message, the code splits the original entry into a left fragment (psge) and a right fragment (rsge). The right fragment's page-local offset should be advanced by the fragment-local delta (start - offset), where offset is the cumulative byte position at the start of the current SG entry. Instead, the code incorrectly advances rsge.offset by the message-global insertion point `start`, which over-advances the offset by `offset` bytes for any non-first SG entry. This produces an inconsistent scatterlist layout where the right fragment points to the wrong location within its page, potentially causing out-of-bounds reads or writes when the corrupted scatterlist is subsequently processed. The fix changes `rsge.offset += start` to `rsge.offset += start - offset`, using the correct fragment-local delta. The attack surface requires a local user to load and attach a BPF sk_msg program that calls bpf_msg_push_data() with an insertion point in a non-first scatterlist entry, which requires CAP_BPF or equivalent privilege. Exploitation requires heap grooming to turn the offset corruption into a controlled write primitive, making AC:High appropriate.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.1 | 4.20 | 6.1.176 | aeb95146848d |
| 6.12 | 4.20 | 6.12.93 | 3075c21d2d76 |
| 6.18 | 4.20 | 6.18.35 | 5e1902866796 |
| 7.0 | 4.20 | 7.0.12 | 63f64a510c79 |
| 6.6 | 4.20 | 6.6.143 | 96b72672ce84 |
| mainline | 4.20 | 7.1 | f72eed9b84fb |
| 5.15 | 4.20 | 5.15.210 | d81b323af2dc |
| 5.10 | 4.20 | 5.10.259 | f14609d81467 |