CVE-2026-63865

Source
https://cve.org/CVERecord?id=CVE-2026-63865
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63865.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-63865
Downstream
Published
2026-07-19T14:04:51.215Z
Modified
2026-07-22T03:31:56.947892673Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks
Details

In the Linux kernel, the following vulnerability has been resolved:

bpf: Drop tasktoinode and inetconnestablished from lsm sleepable hooks

bpflsmtasktoinode() is called under rcureadlock() and bpflsminetconnestablished() is called from softirq context, so neither hook can be used by sleepable LSM programs.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63865.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
423f16108c9d832bd96059d5c882c8ef6d76eb96
Fixed
452a927cddcd67478d030e646f41cb904a93156f
Fixed
f0fc2a9828171205244a28013f02889f50b71c9f
Fixed
26b380a3ca0b605fd8860995ed6a208f276dd316
Fixed
0d918263c9bfc86078edb2e2f7302a0c6ce42b7c
Fixed
281f2a214565a5cbf8b7355a65738d80bd19b8c5
Fixed
989f1b93907de1753a814996222da375f07e579b
Fixed
beaf0e96b1da74549a6cabd040f9667d83b2e97e

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63865.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.209
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.141
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.91
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.33
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.10

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-63865.json"