Linux Kernel

•

severity

9.1

published

The Linux kernel's TIPC broadcast path can read beyond a network packet buffer when processing a malformed Gap ACK blocks record. An unauthenticated network peer can advertise an oversized block count in a short broadcast state message, potentially disclosing kernel memory or crashing the system.

tipc_get_gap_ack_blks() verified that the record's declared length was internally consistent with its ACK counts, but the broadcast caller did not check that the record fit within the message data area. tipc_link_advance_transmq() could consequently pass an attacker-controlled size to kmemdup() and read beyond the receive skb. The fix applies the message-length bound already used by the unicast path and discards malformed broadcast state messages. Bynario classifies the issue as CWE-125.


References

CVSS v3.1

9.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

CVSS v3.1

9.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

CVSS v3.1

9.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

SMt0a0r#t&  lOo7o4kOiAnNg1  aHt3  yWo4u0rQ  s$oEfEtRwWaArRe0  cFrJi#t&iGcKa3lJl@yX.2

request briefing

request briefing

SSt&aIr$tS  l%oCo4kOi9nXgQ  aYtB  yAoXu%r4  s9oHfCt&wPaUrXe6  cJr7i5tVi$cNa2l#lYyY.#

request briefing

request briefing

S9t&a6rLt%  lOoMoWk9iAnQgP  aCtM  yPoXuHrH  sLoHf4t9w&a2rBe5  cNr%iPtNiLcOa7l6lCyG.O

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026