CVE-2026-63970
CVE CVE-2026-63970EUVD EUVD-2026-45743Published 2026-07-19T14:55:57.000ZLast changed 2026-08-05T12:37:41.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: bind uarg before filling zerocopy skb virtio_transport_send_pkt_info() allocates or reuses the zerocopy uarg before entering the send loop, but virtio_transport_alloc_skb() still fills the skb before it inherits that uarg. When fixed-buffer vectored zerocopy hits MAX_SKB_FRAGS, io_sg_from_iter() may partially attach managed frags and return -EMSGSIZE. The rollback path call kfree_skb() to free an skb that carries SKBFL_MANAGED_FRAG_REFS but no uarg, so skb_release_data() falls through to ordinary frag unref. Pass the uarg into virtio_transport_alloc_skb() and bind it immediately before virtio_transport_fill_skb(). This keeps control or no-payload skbs untouched while ensuring success and rollback share one lifetime rule.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 0; 581512a6dc939ef122e49336626ae159f3b8a345 <72194f65050958e4c8e069adb6c5d89ef81ca197; 581512a6dc939ef122e49336626ae159f3b8a345 <1e584c304cfb94a759417130b1fc6d30b30c4cce; 581512a6dc939ef122e49336626ae159f3b8a345 <5d317573f1d48e76cce5fb6250452b6e4102e0fb; 6.7; patch: 7.1; patch: 6.18.35; patch: 7.0.12; patch: 6.12.97; 581512a6dc939ef122e49336626ae159f3b8a345 <b62e2b2b4a50953ca952f3cd3f77dd62dc50fd5d
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.