GHSA-39fm-rjr2-46w3HighCVSS 8.4

In the Linux kernel, the following vulnerability has been resolved: bpf: sockmap: fix tail...

Published
July 19, 2026
Last Modified
July 20, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

bpf: sockmap: fix tail fragment offset in bpf_msg_push_data

When bpf_msg_push_data() inserts data in the middle of a scatterlist entry, it splits the original entry into a left fragment and a right fragment.

The right fragment offset is page-local, but the code advances it with start, which is the message-global insertion point. For inserts into a non-first SG entry, this over-advances the offset and leaves the split layout inconsistent.

Advance the right fragment offset by the fragment-local delta, start - offset, which matches the length removed from the front of the original entry.

🔗 References (10)