All of lore.kernel.org
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-74282: tipc: prevent snt_unacked underflow on CONN_ACK
Date: Sat, 15 Aug 2026 15:10:09 +0900	[thread overview]
Message-ID: <2026081546-CVE-2026-74282-5b9f@gregkh> (raw)

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

tipc: prevent snt_unacked underflow on CONN_ACK

tipc_sk_conn_proto_rcv() subtracts the peer-supplied connection ack count
from the unsigned 16-bit send counter snt_unacked without checking that it
does not exceed the number of messages actually outstanding:

	tsk->snt_unacked -= msg_conn_ack(hdr);

msg_conn_ack() is read straight from a received CONN_MANAGER/CONN_ACK
message. If the ack count is larger than snt_unacked, the subtraction
wraps to a near-maximum value, leaving tsk_conn_cong() permanently true
and starving the connection of further transmits.

Validate the ACK count at the start of the CONN_ACK block and drop the
message if it acknowledges more messages than are outstanding. A peer (or,
for a local connection, the connected peer socket) can otherwise wedge a
TIPC connection's send side by sending an oversized connection ack.

The Linux kernel CVE team has assigned CVE-2026-74282 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 4.7 with commit 10724cc7bb7832b482df049c20fd824d928c5eaa and fixed in 5.10.261 with commit 3388145d258cf2c4c98278e3987296007d30672e
	Issue introduced in 4.7 with commit 10724cc7bb7832b482df049c20fd824d928c5eaa and fixed in 5.15.212 with commit 67e55b054bf8025658dc0e255057f2a6236416bd
	Issue introduced in 4.7 with commit 10724cc7bb7832b482df049c20fd824d928c5eaa and fixed in 6.1.178 with commit 96f91b8ae1a489b3eca137e7acf42cf985fb8939
	Issue introduced in 4.7 with commit 10724cc7bb7832b482df049c20fd824d928c5eaa and fixed in 6.6.145 with commit 47ed873e4ceda34098bd46d8e96b4bb13cad3a04
	Issue introduced in 4.7 with commit 10724cc7bb7832b482df049c20fd824d928c5eaa and fixed in 6.12.97 with commit b44bebdd32c9ff66ee2aebfc317ced44bedd9335
	Issue introduced in 4.7 with commit 10724cc7bb7832b482df049c20fd824d928c5eaa and fixed in 6.18.40 with commit 3cfa3d8e0dc167850edeb5bf5a07757db83fd54e
	Issue introduced in 4.7 with commit 10724cc7bb7832b482df049c20fd824d928c5eaa and fixed in 7.1.5 with commit 1e2c956745777e6ffdee7f30da5935741c03ee1e
	Issue introduced in 4.7 with commit 10724cc7bb7832b482df049c20fd824d928c5eaa and fixed in 7.2-rc1 with commit ab3e10b44ba5411779aac7afd2477917dd77750f

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-74282
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	net/tipc/socket.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/3388145d258cf2c4c98278e3987296007d30672e
	https://git.kernel.org/stable/c/67e55b054bf8025658dc0e255057f2a6236416bd
	https://git.kernel.org/stable/c/96f91b8ae1a489b3eca137e7acf42cf985fb8939
	https://git.kernel.org/stable/c/47ed873e4ceda34098bd46d8e96b4bb13cad3a04
	https://git.kernel.org/stable/c/b44bebdd32c9ff66ee2aebfc317ced44bedd9335
	https://git.kernel.org/stable/c/3cfa3d8e0dc167850edeb5bf5a07757db83fd54e
	https://git.kernel.org/stable/c/1e2c956745777e6ffdee7f30da5935741c03ee1e
	https://git.kernel.org/stable/c/ab3e10b44ba5411779aac7afd2477917dd77750f

                 reply	other threads:[~2026-08-15  6:32 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2026081546-CVE-2026-74282-5b9f@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=gregkh@kernel.org \
    --cc=linux-cve-announce@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.