{"schema_version":"1.9.0","id":"CVE-2026-63926","published":"2026-07-19T14:55:27.154Z","modified":"2026-08-12T03:51:18.404778153Z","summary":"bpf: sockmap: fix tail fragment offset in bpf_msg_push_data","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: sockmap: fix tail fragment offset in bpf_msg_push_data\n\nWhen bpf_msg_push_data() inserts data in the middle of a scatterlist\nentry, it splits the original entry into a left fragment and a right\nfragment.\n\nThe right fragment offset is page-local, but the code advances it with\n`start`, which is the message-global insertion point. For inserts into a\nnon-first SG entry, this over-advances the offset and leaves the split\nlayout inconsistent.\n\nAdvance the right fragment offset by the fragment-local delta,\n`start - offset`, which matches the length removed from the front of the\noriginal entry.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"6fff607e2f14bd7c63c06c464a6f93b8efbabe28"},{"fixed":"f14609d8146707452e0822f3c8154674ce677251"},{"fixed":"d81b323af2dcee47573907ccb89c0df9b45cb2e2"},{"fixed":"aeb95146848d12206e1b2cfacd4f40e21ce81d94"},{"fixed":"96b72672ce849a1402730238e64d9b20bf06a96d"},{"fixed":"3075c21d2d76c0067f4a382765b43d6cc10470f1"},{"fixed":"5e19028667963fb371ebb00cecc2a473ef92056b"},{"fixed":"63f64a510c7917658ddf4d073ece73914ee25346"},{"fixed":"f72eed9b84fb771019a955908132410a9ba9ea3f"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63926.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.20.0"},{"fixed":"5.10.259"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.210"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.176"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.143"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.93"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.35"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.12"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63926.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/3075c21d2d76c0067f4a382765b43d6cc10470f1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5e19028667963fb371ebb00cecc2a473ef92056b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/63f64a510c7917658ddf4d073ece73914ee25346"},{"type":"WEB","url":"https://git.kernel.org/stable/c/96b72672ce849a1402730238e64d9b20bf06a96d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/aeb95146848d12206e1b2cfacd4f40e21ce81d94"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d81b323af2dcee47573907ccb89c0df9b45cb2e2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f14609d8146707452e0822f3c8154674ce677251"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f72eed9b84fb771019a955908132410a9ba9ea3f"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63926.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63926"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63926.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}