{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "d3b18ad31f93d0b6bae105c679018a1ba7daa9ca"
            },
            {
              "fixed": "f126eed589eec6f201405abbc398844042ef6d57"
            },
            {
              "fixed": "31a110642b5fb5e61940cbcfb503445ac4f28017"
            },
            {
              "fixed": "9bb86d8184b37503816150c4a6ad3c17dfdbe827"
            },
            {
              "fixed": "0eb4c16c4adb262763bda870a8ed38a1a9dec7ec"
            },
            {
              "fixed": "d22cc92bc41290e5783a72375e0843d9435f6001"
            },
            {
              "fixed": "1acdd14c0990dd1cd4b6534f00366d2e6dfce05f"
            },
            {
              "fixed": "21ed9540a8e1906dfcbc1bb82ba9b4de4fa4bd6d"
            },
            {
              "fixed": "406e8a651a7b854c41fecd5117bb282b3a6c2c6b"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.20.0"
            },
            {
              "fixed": "5.10.261"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.11.0"
            },
            {
              "fixed": "5.15.212"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.16.0"
            },
            {
              "fixed": "6.1.177"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.144"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.95"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.38"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.1.3"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63830.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skmsg: preserve sg.copy across SG transforms\n\nThe sk_msg sg.copy bitmap is part of the scatterlist entry ownership\nstate. A set bit tells sk_msg_compute_data_pointers() not to expose the\nentry through writable BPF ctx-\u003edata. This protects entries backed by\npages that are not private to the sk_msg, such as splice-backed file\npage-cache pages.\n\nSeveral sk_msg transform paths move, copy, split, or compact\nmsg-\u003esg.data[] entries without moving the matching sg.copy bit. This can\nmake an externally backed entry arrive at a new slot with a clear copy\nbit. A later SK_MSG verdict can then expose sg_virt(sge) as writable\nctx-\u003edata and BPF stores can modify the original page cache.\n\nKeep sg.copy synchronized with sg.data[] whenever entries are\ntransferred, shifted, split, or copied into a new sk_msg. Clear the bit\nwhen an entry is replaced by a newly allocated private page or freed.\nThis covers the BPF pull/push/pop helpers, sk_msg_shift_left/right(),\nsk_msg_xfer(), and tls_split_open_record(), including the partial tail\nentry created during TLS open-record splitting.",
  "id": "CVE-2026-63830",
  "modified": "2026-08-18T03:30:54.242936516Z",
  "published": "2026-07-19T12:02:23.741Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/0eb4c16c4adb262763bda870a8ed38a1a9dec7ec"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/1acdd14c0990dd1cd4b6534f00366d2e6dfce05f"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/21ed9540a8e1906dfcbc1bb82ba9b4de4fa4bd6d"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/31a110642b5fb5e61940cbcfb503445ac4f28017"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/406e8a651a7b854c41fecd5117bb282b3a6c2c6b"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/9bb86d8184b37503816150c4a6ad3c17dfdbe827"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/d22cc92bc41290e5783a72375e0843d9435f6001"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/f126eed589eec6f201405abbc398844042ef6d57"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63830.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63830"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
      "type": "CVSS_V3"
    }
  ],
  "summary": "net: skmsg: preserve sg.copy across SG transforms"
}