-

CVE-2026-68289

tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()

In the Linux kernel, the following vulnerability has been resolved:

tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()

In tipc_recvmsg(), the copy length is computed as:

  copy = min_t(int, dlen - offset, buflen);

buflen is size_t but min_t(int, ...) casts it to int. When buflen
exceeds INT_MAX (e.g. 0xFFFFFFFF via io_uring provided buffers), it
wraps negative, wins the comparison, and the negative copy length
propagates to simple_copy_to_iter() where int-to-size_t promotion
makes it SIZE_MAX, triggering a WARN_ON. tipc_recvstream() has the
same pattern.

  Kernel panic - not syncing: kernel: panic_on_warn set ...
  RIP: 0010:simple_copy_to_iter+0x9e/0xd0 (net/core/datagram.c:521)
  Call Trace:
   __skb_datagram_iter+0x123/0x8b0 (net/core/datagram.c:402)
   skb_copy_datagram_iter+0x77/0x1a0 (net/core/datagram.c:534)
   tipc_recvmsg+0x3d7/0xe80 (net/tipc/socket.c:1934)
   io_recvmsg+0x47e/0xda0

Fix by changing min_t(int, ...) to min_t(size_t, ...) in both
functions. The result is always <= (dlen - offset), which is bounded
by TIPC maximum message size (0x1ffff bytes), so the implicit
narrowing on assignment to int copy is always safe.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version e9f8b10101c6da3ab000a2fb17162374c9bd2c69
Version < 9fd4f92671146b068809b6c34b50346cb30cf8f7
Status affected
Version e9f8b10101c6da3ab000a2fb17162374c9bd2c69
Version < 93580911f02d1f4a506ec0a6fc4354140c53ffe8
Status affected
Version e9f8b10101c6da3ab000a2fb17162374c9bd2c69
Version < 1b6066313b9b8fac870483bf7a26d6bd56579747
Status affected
Version e9f8b10101c6da3ab000a2fb17162374c9bd2c69
Version < 7364014fdc289225229eb08de8bcbf4580e78e4d
Status affected
Version e9f8b10101c6da3ab000a2fb17162374c9bd2c69
Version < fe9bf32bb18f2d35789d4960fb007d1059bbaa38
Status affected
Version e9f8b10101c6da3ab000a2fb17162374c9bd2c69
Version < 47f42ff521b4eeb46e82f9a46a4783a99f7570d7
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.12
Status affected
Version 0
Version < 4.12
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.059
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/fe9bf32bb18f2d35789d4960fb007d1059bbaa38
https://git.kernel.org/stable/c/47f42ff521b4eeb46e82f9a46a4783a99f7570d7
https://git.kernel.org/stable/c/1b6066313b9b8fac870483bf7a26d6bd56579747
https://git.kernel.org/stable/c/7364014fdc289225229eb08de8bcbf4580e78e4d
https://git.kernel.org/stable/c/93580911f02d1f4a506ec0a6fc4354140c53ffe8
https://git.kernel.org/stable/c/9fd4f92671146b068809b6c34b50346cb30cf8f7