Release of invalid pointer or reference in Linux kernel - CVE-2026-63809
Published: July 21, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to memory corruption in proc_sys_call_handler and __cgroup_bpf_run_filter_sysctl() when processing a sysctl write that replaces the temporary buffer. A local privileged user can write a crafted sysctl value to trigger memory corruption and cause a denial of service.
Exploitation requires access to write to a sysctl entry from a task in the target cgroup, and the fault was reproduced while writing to /proc/sys/kernel/domainname.
Affected software
How to mitigate CVE-2026-63809
External References
- https://git.kernel.org/stable/c/4c21b5927d4364bfe7365f2700da5fea0ed0d004
- https://git.kernel.org/stable/c/65bd0c0afb0e1bf3287458e342429b069624f7d4
- https://git.kernel.org/stable/c/70df4de46577fab5e25418f014583155a147c902
- https://git.kernel.org/stable/c/77355ef7a9f6b0d2bdf65be3b37f2c1f365e20d2
- https://git.kernel.org/stable/c/81fc9a13acae99966232f0e055eb2e445263b89a
- https://git.kernel.org/stable/c/838fe9c28121777c59a9406710a68fcf77bb8017
- https://git.kernel.org/stable/c/d0a81ed5ff5d0f9c3f63a4f9e5a4642c363ecd3e
- https://git.kernel.org/stable/c/e1d1e203a6000804c5d3b8a4aa4e52303c0c7ab2