{"schema_version":"1.9.0","id":"CVE-2026-63952","published":"2026-07-19T14:55:44.809Z","modified":"2026-08-31T18:26:08.108437133Z","related":["ALSA-2026:57251","ALSA-2026:57252","SUSE-SU-2026:23066-1","SUSE-SU-2026:23068-1","SUSE-SU-2026:23193-1","SUSE-SU-2026:23194-1","SUSE-SU-2026:23221-1","SUSE-SU-2026:23231-1","SUSE-SU-2026:23237-1","SUSE-SU-2026:23241-1","SUSE-SU-2026:23244-1","SUSE-SU-2026:3602-1","SUSE-SU-2026:3790-1","SUSE-SU-2026:3810-1","openSUSE-SU-2026:21555-1"],"summary":"memfd: deny writeable mappings when implying SEAL_WRITE","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmemfd: deny writeable mappings when implying SEAL_WRITE\n\nWhen SEAL_EXEC is added, SEAL_WRITE is implied to make W^X.  But the\nimplied seal is set after the check that makes sure the memfd can not have\nany writable mappings.  This means one can use SEAL_EXEC to apply\nSEAL_WRITE while having writeable mappings.\n\nThis breaks the contract that SEAL_WRITE provides and can be used by an\nattacker to pass a memfd that appears to be write sealed but can still be\nmodified arbitrarily.\n\nFix this by adding the implied seals before the call for\nmapping_deny_writable() is done.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"c4f75bc8bd6b3d62665e1f5400c419540edb5601"},{"fixed":"b3f4f82d1315f1439059a83d1c22c51a5b43d99e"},{"fixed":"3be2a24f7f72ad7321ed6ad1715b956a4527bcf4"},{"fixed":"0995d1f79aed8ccbf62056189dd53fd19726ea08"},{"fixed":"555702282d4536a865dfffb1cd4f6028f196e7e8"},{"fixed":"3b041514cb6eae45869b020f743c14d983363222"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63952.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.3.0"},{"fixed":"6.6.143"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.93"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.35"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.12"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63952.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0995d1f79aed8ccbf62056189dd53fd19726ea08"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3b041514cb6eae45869b020f743c14d983363222"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3be2a24f7f72ad7321ed6ad1715b956a4527bcf4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/555702282d4536a865dfffb1cd4f6028f196e7e8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b3f4f82d1315f1439059a83d1c22c51a5b43d99e"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63952.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63952"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63952.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}