KernelScan.io

HIGH Introduced in 4.20

bpf sockmap PushData OOB

CVE-2026-63926

CVSS 8.4 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI6.7MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data When bpf_msg_push_data() inserts data in the middle of a scatterlist entry, it splits the original entry into a left fragment and a right fragment. The right fragment offset is page-local, but the code advances it with `start`, which is the message-global insertion point. For inserts into a non-first SG entry, this over-advances the offset and leaves the split layout inconsistent. Advance the right fragment offset by the fragment-local delta, `start - offset`, which matches the length removed from the front of the original entry.

02

Engine v0.4.0

Risk summary

A local user with access to BPF sockmap programs can trigger an incorrect scatterlist fragment offset calculation in bpf_msg_push_data(), causing memory corruption in kernel heap structures. Successful exploitation could allow privilege escalation or kernel code execution, though heap grooming is required to reliably exploit the corruption.

Affectednet/core/filter.c (BPF sockmap sk_msg helper)

Vulnerability analysis

The bug is in bpf_msg_push_data() in net/core/filter.c. When inserting data into the middle of a scatterlist entry that is not the first entry in the message, the code splits the original entry into a left fragment (psge) and a right fragment (rsge). The right fragment's page-local offset should be advanced by the fragment-local delta (start - offset), where offset is the cumulative byte position at the start of the current SG entry. Instead, the code incorrectly advances rsge.offset by the message-global insertion point `start`, which over-advances the offset by `offset` bytes for any non-first SG entry. This produces an inconsistent scatterlist layout where the right fragment points to the wrong location within its page, potentially causing out-of-bounds reads or writes when the corrupted scatterlist is subsequently processed. The fix changes `rsge.offset += start` to `rsge.offset += start - offset`, using the correct fragment-local delta. The attack surface requires a local user to load and attach a BPF sk_msg program that calls bpf_msg_push_data() with an insertion point in a non-first scatterlist entry, which requires CAP_BPF or equivalent privilege. Exploitation requires heap grooming to turn the offset corruption into a controlled write primitive, making AC:High appropriate.

03

BranchIntroducedFixed inPatch commit
6.14.206.1.176aeb95146848d
6.124.206.12.933075c21d2d76
6.184.206.18.355e1902866796
7.04.207.0.1263f64a510c79
6.64.206.6.14396b72672ce84
mainline4.207.1f72eed9b84fb
5.154.205.15.210d81b323af2dc
5.104.205.10.259f14609d81467