Linux Kernel Memory Corruption in Task Management from Vendor
CVE-2026-63799

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63799?

A memory corruption vulnerability exists in the Linux kernel due to an out-of-bounds write occurring during task management. Particularly, when transitioning certain task identifiers, the system may unintentionally clear a bit in memory beyond the intended bounds. This happens when the active task has an identifier set to a sentinel value, leading to a deterministic memory corruption at a specific offset. The situation arises only under specific conditions when a CPU handles a task with an unset identifier, allowing a sequence of operations to lead to the corruption of adjacent kernel memory. Safeguards have been implemented to prevent this unwanted behavior by ensuring that only genuine task-owned identifiers trigger this operation.

Affected Version(s)

Linux fbd0e71dc370af73f6b316e4de9eed273dd90340 < 8d32856fb72ba976d9c87ba405fd17e80419934c

Linux fbd0e71dc370af73f6b316e4de9eed273dd90340

Linux 6.19

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.