Answer in brief
CVE-2026-63830 records a Unknown severity vulnerability in net: skmsg: preserve sg.copy across SG transforms. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-63830 records a Unknown severity vulnerability in net: skmsg: preserve sg.copy across SG transforms. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d3b18ad31f93d0b6bae105c679018a1ba7daa9ca <f126eed589eec6f201405abbc398844042ef6d57 || >=d3b18ad31f93d0b6bae105c679018a1ba7daa9ca <31a110642b5fb5e61940cbcfb503445ac4f28017 || >=d3b18ad31f93d0b6bae105c679018a1ba7daa9ca <9bb86d8184b37503816150c4a6ad3c17dfdbe827 || >=d3b18ad31f93d0b6bae105c679018a1ba7daa9ca <0eb4c16c4adb262763bda870a8ed38a1a9dec7ec || >=d3b18ad31f93d0b6bae105c679018a1ba7daa9ca <d22cc92bc41290e5783a72375e0843d9435f6001 || >=d3b18ad31f93d0b6bae105c679018a1ba7daa9ca <1acdd14c0990dd1cd4b6534f00366d2e6dfce05f || >=d3b18ad31f93d0b6bae105c679018a1ba7daa9ca <21ed9540a8e1906dfcbc1bb82ba9b4de4fa4bd6d || >=d3b18ad31f93d0b6bae105c679018a1ba7daa9ca <406e8a651a7b854c41fecd5117bb282b3a6c2c6b | f126eed589eec6f201405abbc398844042ef6d57, 31a110642b5fb5e61940cbcfb503445ac4f28017, 9bb86d8184b37503816150c4a6ad3c17dfdbe827, 0eb4c16c4adb262763bda870a8ed38a1a9dec7ec, d22cc92bc41290e5783a72375e0843d9435f6001, 1acdd14c0990dd1cd4b6534f00366d2e6dfce05f, 21ed9540a8e1906dfcbc1bb82ba9b4de4fa4bd6d, 406e8a651a7b854c41fecd5117bb282b3a6c2c6b |
| Linux/Linuxgeneric | 4.20 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net: skmsg: preserve sg.copy across SG transforms The sk_msg sg.copy bitmap is part of the scatterlist entry ownership state. A set bit tells sk_msg_compute_data_pointers() not to expose the entry through writable BPF ctx->data. This protects entries backed by pages that are not private to the sk_msg, such as splice-backed file page-cache pages. Several sk_msg transform paths move, copy, split, or compact msg->sg.data[] entries without moving the matching sg.copy bit. This can make an externally backed entry arrive at a new slot with a clear copy bit. A later SK_MSG verdict can then expose sg_virt(sge) as writable ctx->data and BPF stores can modify the original page cache. Keep sg.copy synchronized with sg.data[] whenever entries are transferred, shifted, split, or copied into a new sk_msg. Clear the bit when an entry is replaced by a newly allocated private page or freed. This covers the BPF pull/push/pop helpers, sk_msg_shift_left/right(), sk_msg_xfer(), and tls_split_open_record(), including the partial tail entry created during TLS open-record splitting.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d3b18ad31f93d0b6bae105c679018a1ba7daa9ca <f126eed589eec6f201405abbc398844042ef6d57 || >=d3b18ad31f93d0b6bae105c679018a1ba7daa9ca <31a110642b5fb5e61940cbcfb503445ac4f28017 || >=d3b18ad31f93d0b6bae105c679018a1ba7daa9ca <9bb86d8184b37503816150c4a6ad3c17dfdbe827 || >=d3b18ad31f93d0b6bae105c679018a1ba7daa9ca <0eb4c16c4adb262763bda870a8ed38a1a9dec7ec || >=d3b18ad31f93d0b6bae105c679018a1ba7daa9ca <d22cc92bc41290e5783a72375e0843d9435f6001 || >=d3b18ad31f93d0b6bae105c679018a1ba7daa9ca <1acdd14c0990dd1cd4b6534f00366d2e6dfce05f || >=d3b18ad31f93d0b6bae105c679018a1ba7daa9ca <21ed9540a8e1906dfcbc1bb82ba9b4de4fa4bd6d || >=d3b18ad31f93d0b6bae105c679018a1ba7daa9ca <406e8a651a7b854c41fecd5117bb282b3a6c2c6b | f126eed589eec6f201405abbc398844042ef6d57, 31a110642b5fb5e61940cbcfb503445ac4f28017, 9bb86d8184b37503816150c4a6ad3c17dfdbe827, 0eb4c16c4adb262763bda870a8ed38a1a9dec7ec, d22cc92bc41290e5783a72375e0843d9435f6001, 1acdd14c0990dd1cd4b6534f00366d2e6dfce05f, 21ed9540a8e1906dfcbc1bb82ba9b4de4fa4bd6d, 406e8a651a7b854c41fecd5117bb282b3a6c2c6b |
| Linux/Linuxgeneric | 4.20 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net: skmsg: preserve sg.copy across SG transforms The sk_msg sg.copy bitmap is part of the scatterlist entry ownership state. A set bit tells sk_msg_compute_data_pointers() not to expose the entry through writable BPF ctx->data. This protects entries backed by pages that are not private to the sk_msg, such as splice-backed file page-cache pages. Several sk_msg transform paths move, copy, split, or compact msg->sg.data[] entries without moving the matching sg.copy bit. This can make an externally backed entry arrive at a new slot with a clear copy bit. A later SK_MSG verdict can then expose sg_virt(sge) as writable ctx->data and BPF stores can modify the original page cache. Keep sg.copy synchronized with sg.data[] whenever entries are transferred, shifted, split, or copied into a new sk_msg. Clear the bit when an entry is replaced by a newly allocated private page or freed. This covers the BPF pull/push/pop helpers, sk_msg_shift_left/right(), sk_msg_xfer(), and tls_split_open_record(), including the partial tail entry created during TLS open-record splitting.
Quoted source text, attributed separately from HOL analysis.