CVE-2026-63926

HIGHCVSS 8.4/10EPSS 0.18%

Last modified

CVE-2026-63926 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data When bpf_msg_push_data() inserts data in the middle of a scatterlist entry, it splits the original entry into a left fragment and a right fragment. The right fragment offset is page-local, but the code advances it with `start`, which is the message-global insertion point. For inserts into a non-first SG entry, this over-advances the offset and leaves the split layout inconsistent. Advance the right fragment offset by the fragment-local delta, `start - offset`, which matches the length removed from the front of the original entry.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data When bpf_msg_push_data() inserts data in the middle of a scatterlist entry, it splits the original entry into a left fragment and a right fragment. The right fragment offset is page-local, but the code advances it with `start`, which is the message-global insertion point. For inserts into a non-first SG entry, this over-advances the offset and leaves the split layout inconsistent. Advance the right fragment offset by the fragment-local delta, `start - offset`, which matches the length removed from the front of the original entry.

Metrics

CVSS 3.1
8.4/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.18%

7.8th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 6fff607e2f14bd7c63c06c464a6f93b8efbabe28, < f14609d8146707452e0822f3c8154674ce677251; >= 6fff607e2f14bd7c63c06c464a6f93b8efbabe28, < d81b323af2dcee47573907ccb89c0df9b45cb2e2; >= 6fff607e2f14bd7c63c06c464a6f93b8efbabe28, < aeb95146848d12206e1b2cfacd4f40e21ce81d94; >= 6fff607e2f14bd7c63c06c464a6f93b8efbabe28, < 96b72672ce849a1402730238e64d9b20bf06a96d; >= 6fff607e2f14bd7c63c06c464a6f93b8efbabe28, < 3075c21d2d76c0067f4a382765b43d6cc10470f1; >= 6fff607e2f14bd7c63c06c464a6f93b8efbabe28, < 5e19028667963fb371ebb00cecc2a473ef92056b; >= 6fff607e2f14bd7c63c06c464a6f93b8efbabe28, < 63f64a510c7917658ddf4d073ece73914ee25346; >= 6fff607e2f14bd7c63c06c464a6f93b8efbabe28, < f72eed9b84fb771019a955908132410a9ba9ea3f
LinuxLinux4.20

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-63926?
In the Linux kernel, the following vulnerability has been resolved: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data When bpf_msg_push_data() inserts data in the middle of a scatterlist entry, it splits the original entry into a left fragment and a right fragment. The right fragment offset is page-local, but the code advances it with `start`, which is the message-global insertion point. For inserts into a non-first SG entry, this over-advances the offset and leaves the split layout inconsistent. Advance the right fragment offset by the fragment-local delta, `start - offset`, which matches the length removed from the front of the original entry.
How severe is CVE-2026-63926?
CVE-2026-63926 has a CVSS score of 8.4/10 (HIGH severity). The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2026-63926?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-63926?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST