-
CVE-2026-68289
- EPSS 0.16%
- Veröffentlicht 10.08.2026 12:02:22
- Zuletzt bearbeitet 03.10.2026 11:17:36
- Erkennungen
tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()
In the Linux kernel, the following vulnerability has been resolved: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() In tipc_recvmsg(), the copy length is computed as: copy = min_t(int, dlen - offset, buflen); buflen is size_t but min_t(int, ...) casts it to int. When buflen exceeds INT_MAX (e.g. 0xFFFFFFFF via io_uring provided buffers), it wraps negative, wins the comparison, and the negative copy length propagates to simple_copy_to_iter() where int-to-size_t promotion makes it SIZE_MAX, triggering a WARN_ON. tipc_recvstream() has the same pattern. Kernel panic - not syncing: kernel: panic_on_warn set ... RIP: 0010:simple_copy_to_iter+0x9e/0xd0 (net/core/datagram.c:521) Call Trace: __skb_datagram_iter+0x123/0x8b0 (net/core/datagram.c:402) skb_copy_datagram_iter+0x77/0x1a0 (net/core/datagram.c:534) tipc_recvmsg+0x3d7/0xe80 (net/tipc/socket.c:1934) io_recvmsg+0x47e/0xda0 Fix by changing min_t(int, ...) to min_t(size_t, ...) in both functions. The result is always <= (dlen - offset), which is bounded by TIPC maximum message size (0x1ffff bytes), so the implicit narrowing on assignment to int copy is always safe.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
e9f8b10101c6da3ab000a2fb17162374c9bd2c69
Version <
9fd4f92671146b068809b6c34b50346cb30cf8f7
Status
affected
Version
e9f8b10101c6da3ab000a2fb17162374c9bd2c69
Version <
93580911f02d1f4a506ec0a6fc4354140c53ffe8
Status
affected
Version
e9f8b10101c6da3ab000a2fb17162374c9bd2c69
Version <
1b6066313b9b8fac870483bf7a26d6bd56579747
Status
affected
Version
e9f8b10101c6da3ab000a2fb17162374c9bd2c69
Version <
7364014fdc289225229eb08de8bcbf4580e78e4d
Status
affected
Version
e9f8b10101c6da3ab000a2fb17162374c9bd2c69
Version <
fe9bf32bb18f2d35789d4960fb007d1059bbaa38
Status
affected
Version
e9f8b10101c6da3ab000a2fb17162374c9bd2c69
Version <
47f42ff521b4eeb46e82f9a46a4783a99f7570d7
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
4.12
Status
affected
Version
0
Version <
4.12
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.1.*
Version
7.1.6
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.059 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/fe9bf32bb18f2d35789d4960fb007d1059bbaa38
https://git.kernel.org/stable/c/47f42ff521b4eeb46e82f9a46a4783a99f7570d7
https://git.kernel.org/stable/c/1b6066313b9b8fac870483bf7a26d6bd56579747
https://git.kernel.org/stable/c/7364014fdc289225229eb08de8bcbf4580e78e4d
https://git.kernel.org/stable/c/93580911f02d1f4a506ec0a6fc4354140c53ffe8
https://git.kernel.org/stable/c/9fd4f92671146b068809b6c34b50346cb30cf8f7