In the Linux kernel, the following vulnerability has been resolved:
bpf: Drop tasktoinode and inetconnestablished from lsm sleepable hooks
bpflsmtasktoinode() is called under rcureadlock() and bpflsminetconnestablished() is called from softirq context, so neither hook can be used by sleepable LSM programs.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63865.json"
}