Out-of-bounds write in Linux kernel - CVE-2026-63794
Published: July 21, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in sev_dbg_crypt() when processing crafted KVM SEV debug encryption requests. A local user can send a crafted ioctl request with page offsets that cause the transfer length to exceed the destination page boundary to cause memory corruption.
The issue affects the encrypt path and can overflow a single-page intermediate buffer by up to 15 bytes when the destination offset is greater than the source offset.
Affected software
openEuler
Ubuntu
bpftool
python3-perf-debuginfo
python3-perf
perf-debuginfo
perf
kernel-tools-devel
kernel-tools-debuginfo
kernel-tools
kernel-source
kernel-headers
kernel-devel
kernel-debugsource
kernel-debuginfo
bpftool-debuginfo
kernel
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
How to mitigate CVE-2026-63794
bpftool - update to 5.10.0-328.0.0.229
python3-perf-debuginfo - update to 5.10.0-328.0.0.229
python3-perf - update to 5.10.0-328.0.0.229
perf-debuginfo - update to 5.10.0-328.0.0.229
perf - update to 5.10.0-328.0.0.229
kernel-tools-devel - update to 5.10.0-328.0.0.229
kernel-tools-debuginfo - update to 5.10.0-328.0.0.229
kernel-tools - update to 5.10.0-328.0.0.229
kernel-source - update to 5.10.0-328.0.0.229
kernel-headers - update to 5.10.0-328.0.0.229
kernel-devel - update to 5.10.0-328.0.0.229
kernel-debugsource - update to 5.10.0-328.0.0.229
kernel-debuginfo - update to 5.10.0-328.0.0.229
bpftool-debuginfo - update to 5.10.0-328.0.0.229
kernel - update to 5.10.0-328.0.0.229
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
External References
- https://git.kernel.org/stable/c/2753a097d1fe24c4351c608048612c74108aa89f
- https://git.kernel.org/stable/c/64f2449841ffc7d203183aa4c748c9c77951ecc5
- https://git.kernel.org/stable/c/720949ed666f34ff28ffdfe1471a5861d1e41fdf
- https://git.kernel.org/stable/c/78ee2d50185a037b3d2452a97f3dad69c3f7f389
- https://git.kernel.org/stable/c/889c2a9c59897ca912bf39df5bb92555a0a13df4
- https://git.kernel.org/stable/c/9349b50f4b11f135fe73b56cb2c2c872d8bc71d7
- https://git.kernel.org/stable/c/e1a0fe288dee07b7da25a71e007c1ecd1080315b
- https://git.kernel.org/stable/c/f701ae476cb92a3a3d8844bb39bb63b4512684c8