Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-63926

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
20/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> bpf: sockmap: fix tail fragment offset in bpf_msg_push_data<br /> <br /> When bpf_msg_push_data() inserts data in the middle of a scatterlist<br /> entry, it splits the original entry into a left fragment and a right<br /> fragment.<br /> <br /> The right fragment offset is page-local, but the code advances it with<br /> `start`, which is the message-global insertion point. For inserts into a<br /> non-first SG entry, this over-advances the offset and leaves the split<br /> layout inconsistent.<br /> <br /> Advance the right fragment offset by the fragment-local delta,<br /> `start - offset`, which matches the length removed from the front of the<br /> original entry.