Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-63830

net: skmsg: preserve sg.copy across SG transforms
Back to all
CVE

CVE-2026-63830

net: skmsg: preserve sg.copy across SG transforms

In the Linux kernel, the following vulnerability has been resolved:

net: skmsg: preserve sg.copy across SG transforms

The sk_msg sg.copy bitmap is part of the scatterlist entry ownership

state. A set bit tells skmsgcomputedatapointers() not to expose the

entry through writable BPF ctx->data. This protects entries backed by

pages that are not private to the sk_msg, such as splice-backed file

page-cache pages.

Several sk_msg transform paths move, copy, split, or compact

msg->sg.data[] entries without moving the matching sg.copy bit. This can

make an externally backed entry arrive at a new slot with a clear copy

bit. A later SKMSG verdict can then expose sgvirt(sge) as writable

ctx->data and BPF stores can modify the original page cache.

Keep sg.copy synchronized with sg.data[] whenever entries are

transferred, shifted, split, or copied into a new sk_msg. Clear the bit

when an entry is replaced by a newly allocated private page or freed.

This covers the BPF pull/push/pop helpers, skmsgshift_left/right(),

skmsgxfer(), and tlssplitopen_record(), including the partial tail

entry created during TLS open-record splitting.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.4
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/0eb4c16c4adb262763bda870a8ed38a1a9dec7ec, https://git.kernel.org/stable/c/1acdd14c0990dd1cd4b6534f00366d2e6dfce05f, https://git.kernel.org/stable/c/21ed9540a8e1906dfcbc1bb82ba9b4de4fa4bd6d, https://git.kernel.org/stable/c/31a110642b5fb5e61940cbcfb503445ac4f28017, https://git.kernel.org/stable/c/406e8a651a7b854c41fecd5117bb282b3a6c2c6b, https://git.kernel.org/stable/c/9bb86d8184b37503816150c4a6ad3c17dfdbe827, https://git.kernel.org/stable/c/d22cc92bc41290e5783a72375e0843d9435f6001, https://git.kernel.org/stable/c/f126eed589eec6f201405abbc398844042ef6d57, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63830.json, https://nvd.nist.gov/vuln/detail/CVE-2026-63830, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.4

CVSS Score
0
10

Basic Information

Base CVSS
9.4
EPSS Probability
0.00372%
EPSS Percentile
0.30224%
Introduced Version
d3b18ad31f93d0b6bae105c679018a1ba7daa9ca,4.20.0,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
406e8a651a7b854c41fecd5117bb282b3a6c2c6b,5.10.261,5.15.212,6.1.177,6.6.144,6.12.95,6.18.38,7.1.3,6.1.177-1,6.12.95-1,0:5.15.0-324.217.5.2.el8uek,0:5.15.0-324.217.5.2.el9uek,0:6.12.0-206.104.3.3.el9uek,0:6.12.0-206.104.3.3.el10uek,0:5.10.262-262.1063.amzn2,0:1.0-0.amzn2,0:5.15.213-150.251.amzn2,1:6.18.38-73.137.amzn2023,1:1.0-0.amzn2023,1:6.12.95-124.187.amzn2023,1:6.1.177-224.371.amzn2023

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading