From mboxrd@z Thu Jan 1 00:00:00 1970 From: AL-KERNEL To: kernel-cve@kernelcve.org Subject: [CVE-2026-63926][MODERATE 7.0] bpf: sockmap: fix tail fragment offset in bpf_msg_push_data Date: Sun, 19 Jul 2026 17:28:18 -0400 Message-ID: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-AL-KERNEL-CVE: CVE-2026-63926 X-AL-KERNEL-Priority: MODERATE 7.0 X-AL-KERNEL-Severity: MODERATE 7.0 X-AL-KERNEL-Base-Severity: MODERATE X-AL-KERNEL-KPANIC: NO X-AL-KERNEL-ActionableScore: 5 X-AL-KERNEL-ActionableScore-Lower: 3 X-AL-KERNEL-Commit: f14609d8146707452e0822f3c8154674ce677251 List-Id: CVE: CVE-2026-63926 Priority: MODERATE 7.0 AL-KERNEL base severity: MODERATE KPANIC flag: NO Patch: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data Commit: f14609d8146707452e0822f3c8154674ce677251 Upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=f14609d8146707452e0822f3c8154674ce677251 Original CVE announcement: https://lore.kernel.org/linux-cve-announce/?q=CVE-2026-63926 Analysis date: Sun, 19 Jul 2026 17:28:18 -0400 ActionableScore: 5 ActionableScore lower bound: 3 Actionable bucket: Actionable Moderate at minimum Manual review required: YES Summary: A wrong page-local scatterlist offset in bpf_msg_push_data() can leave sk_msg fragments inconsistent after insertion into a non-first SG entry, creating a privileged local BPF sockmap path to possible unintended data exposure or kernel crash. ====================================================================== ABOUT THIS REPORT ====================================================================== The original Linux kernel CVE announcement for CVE-2026-63926 is available here: https://lore.kernel.org/linux-cve-announce/?q=CVE-2026-63926 The original announcement does not normally provide a security severity estimate, CVSS assessment, or enough information to determine whether the reported kernel bug represents a practically relevant security issue. This report was generated by AL-KERNEL, an AI-assisted Linux kernel vulnerability analysis system developed by Alexander Larkin. It combines an autonomous classifier with LLM-assisted technical analysis and a separate ActionableScore mechanism. The purpose of this report is to prioritize Linux kernel CVEs before manual review, identify cases that require prompt investigation, and support automatic closure of issues that are unlikely to have meaningful security impact. Published priority for this report: MODERATE 7.0 Manual review required: YES A detailed explanation of the methodology and priority rules is included at the end of this message. ====================================================================== AL-KERNEL CLASSIFICATION RESULT ====================================================================== CVE-2026-63926 MODERATE CHECK WITH IMPACT FROM ORIG NN LOW Maybe valid. Check manually. Hints by AL-KERNEL: The best (paranoid) CVSS is 'AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H';CWE-682;CWE-125;CWE-119;Other CVSS 'AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H';BEST CVSS score: '7.3';DESCR 'bpf_msg_push_data can split a scatterlist entry into a left fragment and a right fragment, but the right fragment offset was advanced by the message global start value instead of the fragment local delta. For inserts into a non first SG entry this can over advance rsge.offset and leave the sk_msg scatterlist layout inconsistent. The resulting SG entry may point at the wrong bytes or outside the intended page fragment, which can lead to incorrect data exposure and kernel instability during later sockmap transmission. For the CVSS the PR:L is used in the paranoid score because some deployments allow reduced capability root, container root, or service accounts to manage BPF and networking objects, while the base score keeps PR:H for normal systems where loading the required BPF sockmap program is administrative. The issue is not directly network reachable by an arbitrary remote peer unless a vulnerable local BPF sockmap policy is already installed and the peer can drive that path. Impact is at least local denial of service and in worst case may include confidentiality impact from out of bounds or unintended page fragment reads.';YES REQUIRES MANUAL CHECK; ,and ActionableScore result is Actionable Moderate at minimum (with actual score 4) YES REMOTE BPF SIMPLEFIX LINUS INCREASED_FROM_LOW_BASED_ON_REQUIREMANUALCHECK DECREASED_TO_MODERATEREG_BASED_ON_ACTIONABLESCORELESSTHAN5 NO NO checked ====================================================================== ACTIONABLESCORE ANALYSIS ====================================================================== ActionableScore=5 ActionableScoreLower=3 ## 1. ActionableScore * Conservative score: 3 * Paranoid score: 5 * Final recommended bucket: **Actionable Moderate at minimum**:: ## 2. Signal breakdown Conservative signals: * Memory layout invariant restoration: +1. The patch restores consistency between scatterlist offset and length after splitting an sk_msg SG entry. * Memory corruption, weak/indirect corruption candidate: +1. The wrong offset can make the right SG fragment point to an unintended page-local location, but the patch does not show attacker-controlled write, reclaim, type confusion, or arbitrary target selection. * Availability impact realistic: +1. An inconsistent SG layout in the sockmap transmit path can plausibly cause kernel instability or crash. * Requires admin/root/CAP_* in typical deployments: -2. Loading and attaching the required BPF sockmap/sk_msg program normally requires CAP_BPF, CAP_NET_ADMIN, CAP_SYS_ADMIN, or root-controlled configuration. Paranoid additional interpretation: * Confidentiality impact plausible: +1. A wrong SG offset may cause transmission of unintended bytes from a page fragment. * Integrity impact plausible: +1. The transmitted message layout may be corrupted or may contain bytes from the wrong fragment. * Reliable kernel crash / strong DoS concern: +1. The affected path is a kernel networking data path where malformed SG metadata can be consumed later by send logic. * Reduced privilege / delegated capability interpretation: privilege penalty reduced from -2 to -1. Some environments delegate BPF or network administration to container root, service accounts, or reduced-capability processes. BPF cap applied: conservative scoring stays below 5 and paranoid scoring stays at 5 because unprivileged BPF is assumed disabled in the evaluated product configuration. Call-site confidence: medium. The patch shows the affected helper and the SG arithmetic, but not all downstream consumers of the malformed sk_msg scatterlist. ## 3. Reachability analysis The bug is locally triggerable by code that can install and run a BPF sockmap/sk_msg program using bpf_msg_push_data(). In typical hardened distributions this is a privileged operation, so the conservative privilege model is admin or CAP_BPF/CAP_NET_ADMIN level access. It is not directly network reachable by an arbitrary remote peer. A remote peer may only drive the path if a vulnerable local BPF sockmap policy is already installed and processes that traffic. Namespaces and containers matter. If a container root or service account is delegated enough BPF and networking capability to create the sockmap setup, the practical PR may be closer to reduced-privilege local access than full host root. The path is not default-exposed like TCP parsing, but BPF sockmap is a high-risk kernel data-plane feature once enabled. ## 4. Severity interpretation This is stronger than an ordinary Moderate correctness bug because it affects scatterlist layout in a kernel networking data path and can plausibly produce unintended memory reads or kernel instability. It is not a clear Important-class issue on the conservative view because the patch does not demonstrate arbitrary write, UAF reclaim, type confusion, object replacement, callback control, or a working LPE path. The paranoid interpretation is Actionable Moderate at minimum. Manual review is justified because the arithmetic bug changes page-local SG offsets and may expose unintended page-fragment data or crash the kernel, but the BPF privilege gate prevents treating it as broadly unprivileged by default. ## 5. One-sentence report phrase A wrong page-local scatterlist offset in bpf_msg_push_data() can leave sk_msg fragments inconsistent after insertion into a non-first SG entry, creating a privileged local BPF sockmap path to possible unintended data exposure or kernel crash. ## 6. Manual review recommendation MANUAL CHECK REQUIRED. YES REQUIRES MANUAL CHECK. Reason: this is a BPF sockmap scatterlist offset bug with plausible memory-safety and data-exposure consequences, but its practical severity depends heavily on BPF privilege configuration and downstream SG consumers. ====================================================================== UPSTREAM PATCH SUMMARY ====================================================================== Patch: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data Commit: f14609d8146707452e0822f3c8154674ce677251 Upstream URL: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=f14609d8146707452e0822f3c8154674ce677251 Commit description: When bpf_msg_push_data() inserts data in the middle of a scatterlist entry, it splits the original entry into a left fragment and a right fragment. The right fragment offset is page-local, but the code advances it with `start`, which is the message-global insertion point. For inserts into a non-first SG entry, this over-advances the offset and leaves the split layout inconsistent. Advance the right fragment offset by the fragment-local delta, `start - offset`, which matches the length removed from the front of the original entry. Fixes: 6fff607 ("bpf: sk_msg program helper bpf_msg_push_data") Cc: stable@kernel.org Reported-by: Yuan Tan Reported-by: Zhengchuan Liang Reported-by: Xin Liu Signed-off-by: Yuqi Xu Signed-off-by: Ren Wei Link: https://patch.msgid.link/8b129d10566aa3eb43f61a8f9757bcf51707d324.1779636774.git.xuyq21@lenovo.com Signed-off-by: Jakub Kicinski Signed-off-by: Greg Kroah-Hartman Changed files: net/core/filter.c Diff excerpt: Not included in this email. See the upstream URL for the full patch. Full patch: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=f14609d8146707452e0822f3c8154674ce677251 ====================================================================== DETAILED REPORT METHODOLOGY ====================================================================== The original Linux kernel CVE announcement for CVE-2026-63926 can be found here: https://lore.kernel.org/linux-cve-announce/?q=CVE-2026-63926 The original CVE announcement normally does not include a security-level estimate. In particular, it may not contain a CVSS assessment, an impact level, or enough information to determine whether the reported bug is a practically relevant security issue. One purpose of this parallel CVE list is to provide that missing technical and prioritization information. The original goal of the AL-KERNEL project was to prioritize Linux kernel CVE analysis automatically before manual review. The system can also help identify non-security issues that may be suitable for automatic closure. This report was generated by AL-KERNEL, an AI-assisted Linux kernel vulnerability analysis system developed by Alexander Larkin. The first analysis stage combines an autonomous classifier with additional LLM-based analysis. The autonomous classifier runs locally on a CPU and is based on a backpropagation neural network. Together, these mechanisms produce a technical vulnerability description, identify likely weakness types, estimate CVSS severity, and provide input for ActionableScore. Two CVSS estimates are retained because incomplete kernel vulnerability information often permits more than one defensible interpretation: Conservative CVSS vector: AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H The Best / paranoid CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H The Best / paranoid CVSS score: 7.3 The conservative vector represents a lower-impact interpretation. The Best/paranoid vector intentionally represents a plausible upper-bound interpretation and should not automatically be treated as demonstrated real-world impact. CVSS may also need to be adjusted for a particular Linux deployment, because actual reachability, privileges, enabled kernel configuration, hardware, namespaces, exposed device nodes, and other environmental conditions can differ significantly between systems. A separate ActionableScore mechanism evaluates practical remediation urgency. Its analysis may include reachability, attack prerequisites, subsystem exposure, memory-corruption characteristics, denial-of-service reliability, and possible confidentiality, integrity, or privilege-escalation impact. Conservative ActionableScore: 3 Paranoid ActionableScore: 5 The final base severity is taken directly from the second tab-separated field of the AL-KERNEL classification result. ActionableScore does not replace or independently override that final AL-KERNEL decision, and if ActionableScore adjusted impact level of ALKERNEL, then you would see self-readable flags above like INCREASED_TO_HIGH_BASED_ON_ACTIONABLESCOREHIGHEREQTHAN7. For an AL-KERNEL result of MODERATE, this report uses the following additional presentation split: ActionableScore below 5 -> MODERATE REGULAR ActionableScore 5 or more -> MODERATE 7.0 The distinction between MODERATE REGULAR and MODERATE 7.0 makes it possible to identify Moderate issues that should receive manual analysis and fixes before lower-priority MODERATE REGULAR issues. In many cases, MODERATE REGULAR fixes may wait for a later rebase or routine update. There is one override in which MODERATE REGULAR becomes MODERATE 7.0 even when the ActionableScore is below 5. When the AL-KERNEL result contains the KPANIC flag, a MODERATE result is always presented as MODERATE 7.0. The KPANIC flag selected with few regexps without usage of AI at all, so it helps to detect cases when Kernel Crash happens and similar (to filter False-Negative results from the LLM usage). KPANIC indicates that a reliable kernel crash, kernel panic, or similarly serious kernel availability impact was identified by the classification workflow. AL-KERNEL base severity for this report: MODERATE KPANIC detected for this report: NO Published priority for this report (same as in Subject): MODERATE 7.0 These results are intended to support engineering triage. They are machine-generated estimates, and cases marked for manual review should be validated by a human security engineer before final disposition. For more info read docs linked from here: https://kernelcve.org/ (and you can submit you own patch there to generate such a report for non-existant CVE-id yet). Note that in many cases this AI tool selects higher severity, than real is (means you can expect Importants instead of Moderate 7.0 or Moderates 7.0 instead of regular Moderates). If you see such cases, please use reply email interface to add additional manual analyses info to this particular CVE. And please, please, let me know when you see Lows instead of Importants or Important instead of Low (because particular for such cases I need to tune this AI tool to make it better for this one and next similar). My contact email for such notifications is alexanjelausa@gmail.com (and both send reply to CVE record itself too and see "reply" button below for howto reply).