CVE-2026-64548 Details
Description
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() When the scatterlist ring is full or nearly full, bpf_msg_push_data() enters a copy fallback path and computes copy + len for the page allocation size. Since len comes from BPF with arg3_type = ARG_ANYTHING and both are u32, a crafted len can wrap the sum to a small value, causing an undersized allocation followed by an out-of-bounds memcpy. BUG: unable to handle page fault for address: ffffed104089a402 Oops: Oops: 0000 [#1] SMP KASAN NOPTI Call Trace: __asan_memcpy (mm/kasan/shadow.c:105) bpf_msg_push_data (net/core/filter.c:2852 net/core/filter.c:2788) bpf_prog_9ed8b5711920a7d7+0x2e/0x36 sk_psock_msg_verdict (net/core/skmsg.c:934) tcp_bpf_sendmsg (net/ipv4/tcp_bpf.c:421 net/ipv4/tcp_bpf.c:584) __sys_sendto (net/socket.c:2206) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) Add an overflow check before the allocation.
A vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) message handling can lead to out-of-bounds memory copying, potentially causing memory corruption. This issue arises in the 'bpf_msg_push_data()' function within the 'net/core/filter.c' file. When the scatterlist ring is full or nearly full, the function falls back to a copy path that calculates the amount of data to be copied based on a length value provided by BPF. Since this length value is a 32-bit unsigned integer, a carefully crafted input can cause an integer overflow, leading to an insufficient memory allocation. This flaw is followed by an out-of-bounds memory copy, which the kernel's Address Sanitizer (KASAN) detects as a page fault error.
Users can update to the latest version of the Linux kernel where this vulnerability has been fixed. The commit that addresses this issue is '0c0a8ed85349dae298712d79cb276acfeb794d82', which adds an overflow check before the memory allocation in the 'bpf_msg_push_data()' function.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 30, 2026 | CVE Modified | kernel.org |
| Jul 27, 2026 | New CVE Received | kernel.org |