8.4

CVE-2026-63952

memfd: deny writeable mappings when implying SEAL_WRITE

In the Linux kernel, the following vulnerability has been resolved:

memfd: deny writeable mappings when implying SEAL_WRITE

When SEAL_EXEC is added, SEAL_WRITE is implied to make W^X.  But the
implied seal is set after the check that makes sure the memfd can not have
any writable mappings.  This means one can use SEAL_EXEC to apply
SEAL_WRITE while having writeable mappings.

This breaks the contract that SEAL_WRITE provides and can be used by an
attacker to pass a memfd that appears to be write sealed but can still be
modified arbitrarily.

Fix this by adding the implied seals before the call for
mapping_deny_writable() is done.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version c4f75bc8bd6b3d62665e1f5400c419540edb5601
Version < b3f4f82d1315f1439059a83d1c22c51a5b43d99e
Status affected
Version c4f75bc8bd6b3d62665e1f5400c419540edb5601
Version < 3be2a24f7f72ad7321ed6ad1715b956a4527bcf4
Status affected
Version c4f75bc8bd6b3d62665e1f5400c419540edb5601
Version < 0995d1f79aed8ccbf62056189dd53fd19726ea08
Status affected
Version c4f75bc8bd6b3d62665e1f5400c419540edb5601
Version < 555702282d4536a865dfffb1cd4f6028f196e7e8
Status affected
Version c4f75bc8bd6b3d62665e1f5400c419540edb5601
Version < 3b041514cb6eae45869b020f743c14d983363222
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.3
Status affected
Version 0
Version < 6.3
Status unaffected
Version <= 6.6.*
Version 6.6.143
Status unaffected
Version <= 6.12.*
Version 6.12.93
Status unaffected
Version <= 6.18.*
Version 6.18.35
Status unaffected
Version <= 7.0.*
Version 7.0.12
Status unaffected
Version <= *
Version 7.1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.061
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.4 2 5.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/b3f4f82d1315f1439059a83d1c22c51a5b43d99e
https://git.kernel.org/stable/c/3be2a24f7f72ad7321ed6ad1715b956a4527bcf4
https://git.kernel.org/stable/c/0995d1f79aed8ccbf62056189dd53fd19726ea08
https://git.kernel.org/stable/c/555702282d4536a865dfffb1cd4f6028f196e7e8
https://git.kernel.org/stable/c/3b041514cb6eae45869b020f743c14d983363222