Linux Kernel

severity

9.1

published

The Linux kernel's TIPC broadcast path can read beyond a network packet buffer when processing a malformed Gap ACK blocks record. An unauthenticated network peer can advertise an oversized block count in a short broadcast state message, potentially disclosing kernel memory or crashing the system.

tipc_get_gap_ack_blks() verified that the record's declared length was internally consistent with its ACK counts, but the broadcast caller did not check that the record fit within the message data area. tipc_link_advance_transmq() could consequently pass an attacker-controlled size to kmemdup() and read beyond the receive skb. The fix applies the message-length bound already used by the unicast path and discards malformed broadcast state messages. Bynario classifies the issue as CWE-125.


References

CVSS v3.1

9.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

CVSS v3.1

9.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

CVSS v3.1

9.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

S7tMaHrYtO  l1oSo&k#iEn5gY  aFtE  yEo1uQr&  sWoQfQt7w8a7r#eF  c@rDi#tHiVcGaRl%lRyN.Z

request briefing

request briefing

SHt2aKrBt4  lPoWoIk5i7n@g#  aEt6  y@oTu1r2  sOoDfYtUw0a6rOeY  c4rLi5t5i9c2aIlUl9yW.Y

request briefing

request briefing

SSt3aOrHtX  lAoMo$kWiFnIg0  aAtI  yCoAuUrW  sLoCfYt7wNa@rZeK  cOrPiPtFiEcMa2lVlRyN.5

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026