SB2026072125 - Release of invalid pointer or reference in Linux kernel bpf
Published: July 21, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Release of invalid pointer or reference (CVE-ID: CVE-2026-63809)
CWE-ID: CWE-763 - Release of invalid pointer or reference
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to memory corruption in proc_sys_call_handler and __cgroup_bpf_run_filter_sysctl() when processing a sysctl write that replaces the temporary buffer. A local privileged user can write a crafted sysctl value to trigger memory corruption and cause a denial of service.
Exploitation requires access to write to a sysctl entry from a task in the target cgroup, and the fault was reproduced while writing to /proc/sys/kernel/domainname.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/4c21b5927d4364bfe7365f2700da5fea0ed0d004
- https://git.kernel.org/stable/c/65bd0c0afb0e1bf3287458e342429b069624f7d4
- https://git.kernel.org/stable/c/70df4de46577fab5e25418f014583155a147c902
- https://git.kernel.org/stable/c/77355ef7a9f6b0d2bdf65be3b37f2c1f365e20d2
- https://git.kernel.org/stable/c/81fc9a13acae99966232f0e055eb2e445263b89a
- https://git.kernel.org/stable/c/838fe9c28121777c59a9406710a68fcf77bb8017
- https://git.kernel.org/stable/c/d0a81ed5ff5d0f9c3f63a4f9e5a4642c363ecd3e
- https://git.kernel.org/stable/c/e1d1e203a6000804c5d3b8a4aa4e52303c0c7ab2