From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7783D380FF4 for ; Sat, 15 Aug 2026 06:32:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786775577; cv=none; b=cpLR2DJ5QD7ocY6Su8eQBVvCTUz4nAnJhb61u83BGMSHDGsZSG1N4noRr2iQfMlgXtw3AivVvP14mBdTuBMQfz2Lva67MQojQrj8uWKBBaZe2h30UbCipNCfppW8URdoChbgk/CWA6FGrSS0D8dgcVNSf6zEs3ZFnx2tKygZkIw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786775577; c=relaxed/simple; bh=eCojir7qmhhIOEnqJQcjbWzrWNxo4wG/uqexpZaMdjs=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=d0VThkJNZgvqH6gbEQSbUctIg1e1yEaIvnOcOq766n7o7hM2BmESE4KopdtS8hu78CQIm7D4T2R0mLp8ZD88BFHXa4U9YsVO8rgqG23DFgFbG+1xJ4KQzl3jnJzBRViz+oZDxxy9OOGVdxBjWU3YvhFw89MAtjr/ywmplo+T2fM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=KGtK08VR; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="KGtK08VR" Received: by smtp.kernel.org (Postfix) with ESMTPSA id C7F051F000E9; Sat, 15 Aug 2026 06:32:55 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1786775576; bh=AqbwRRpRUcOk+QQuIDy+fHIe87R01YtVbC9W/LtXx08=; h=From:To:Cc:Subject:Date:Reply-To; b=KGtK08VR4wmhNgY8c8Ry3nfu1QIG/hpBD6espTLhsLXat6w4tppYvHlSJNyF9VU4W 6ECm9ggh+NB5HMipOkGOb+l7XybNr26rwvkQXrhbG6y0xpEJKX0dqaW7VSCj40u/2L eLt4WiJxg1CZjnzIXkOFgoR4Byo5iLIK1/U1W/oc= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-74282: tipc: prevent snt_unacked underflow on CONN_ACK Date: Sat, 15 Aug 2026 15:10:09 +0900 Message-ID: <2026081546-CVE-2026-74282-5b9f@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3933; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=Kepl9pCTbJFqK6/fCF1wPNSAVExZSfjt0DchBdT2tQs=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkNjGxamdf/3rJbmfPzltCJcBH+yvddGtdbWNn/GS9LS T+/ICqpI5aFQZCJQVZMkeXLNp6j+ysOKXoZ2p6GmcPKBDKEgYtTACYy6THDLOa9NsqLXj9/Y3RE b5p2Wl230eWdHAwLFlzMPv5lxo03LyUXX1zlJvPeYV7sGQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: tipc: prevent snt_unacked underflow on CONN_ACK tipc_sk_conn_proto_rcv() subtracts the peer-supplied connection ack count from the unsigned 16-bit send counter snt_unacked without checking that it does not exceed the number of messages actually outstanding: tsk->snt_unacked -= msg_conn_ack(hdr); msg_conn_ack() is read straight from a received CONN_MANAGER/CONN_ACK message. If the ack count is larger than snt_unacked, the subtraction wraps to a near-maximum value, leaving tsk_conn_cong() permanently true and starving the connection of further transmits. Validate the ACK count at the start of the CONN_ACK block and drop the message if it acknowledges more messages than are outstanding. A peer (or, for a local connection, the connected peer socket) can otherwise wedge a TIPC connection's send side by sending an oversized connection ack. The Linux kernel CVE team has assigned CVE-2026-74282 to this issue. Affected and fixed versions =========================== Issue introduced in 4.7 with commit 10724cc7bb7832b482df049c20fd824d928c5eaa and fixed in 5.10.261 with commit 3388145d258cf2c4c98278e3987296007d30672e Issue introduced in 4.7 with commit 10724cc7bb7832b482df049c20fd824d928c5eaa and fixed in 5.15.212 with commit 67e55b054bf8025658dc0e255057f2a6236416bd Issue introduced in 4.7 with commit 10724cc7bb7832b482df049c20fd824d928c5eaa and fixed in 6.1.178 with commit 96f91b8ae1a489b3eca137e7acf42cf985fb8939 Issue introduced in 4.7 with commit 10724cc7bb7832b482df049c20fd824d928c5eaa and fixed in 6.6.145 with commit 47ed873e4ceda34098bd46d8e96b4bb13cad3a04 Issue introduced in 4.7 with commit 10724cc7bb7832b482df049c20fd824d928c5eaa and fixed in 6.12.97 with commit b44bebdd32c9ff66ee2aebfc317ced44bedd9335 Issue introduced in 4.7 with commit 10724cc7bb7832b482df049c20fd824d928c5eaa and fixed in 6.18.40 with commit 3cfa3d8e0dc167850edeb5bf5a07757db83fd54e Issue introduced in 4.7 with commit 10724cc7bb7832b482df049c20fd824d928c5eaa and fixed in 7.1.5 with commit 1e2c956745777e6ffdee7f30da5935741c03ee1e Issue introduced in 4.7 with commit 10724cc7bb7832b482df049c20fd824d928c5eaa and fixed in 7.2-rc1 with commit ab3e10b44ba5411779aac7afd2477917dd77750f Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74282 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/tipc/socket.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/3388145d258cf2c4c98278e3987296007d30672e https://git.kernel.org/stable/c/67e55b054bf8025658dc0e255057f2a6236416bd https://git.kernel.org/stable/c/96f91b8ae1a489b3eca137e7acf42cf985fb8939 https://git.kernel.org/stable/c/47ed873e4ceda34098bd46d8e96b4bb13cad3a04 https://git.kernel.org/stable/c/b44bebdd32c9ff66ee2aebfc317ced44bedd9335 https://git.kernel.org/stable/c/3cfa3d8e0dc167850edeb5bf5a07757db83fd54e https://git.kernel.org/stable/c/1e2c956745777e6ffdee7f30da5935741c03ee1e https://git.kernel.org/stable/c/ab3e10b44ba5411779aac7afd2477917dd77750f