CVE-2026-68289

Source
https://cve.org/CVERecord?id=CVE-2026-68289
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68289.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68289
Downstream
AZL (1)
BELL (1)
DEBIAN (1)
openSUSE (1)
SUSE (11)
UBUNTU (1)
Related
Published
2026-08-10T12:02:22Z
Modified
2026-09-30T18:26:56Z
Summary
tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()
Details

In the Linux kernel, the following vulnerability has been resolved:

tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()

In tipc_recvmsg(), the copy length is computed as:

copy = min_t(int, dlen - offset, buflen);

buflen is size_t but min_t(int, ...) casts it to int. When buflen exceeds INT_MAX (e.g. 0xFFFFFFFF via io_uring provided buffers), it wraps negative, wins the comparison, and the negative copy length propagates to simple_copy_to_iter() where int-to-size_t promotion makes it SIZE_MAX, triggering a WARN_ON. tipc_recvstream() has the same pattern.

Kernel panic - not syncing: kernel: panic_on_warn set ... RIP: 0010:simple_copy_to_iter+0x9e/0xd0 (net/core/datagram.c:521) Call Trace: __skb_datagram_iter+0x123/0x8b0 (net/core/datagram.c:402) skb_copy_datagram_iter+0x77/0x1a0 (net/core/datagram.c:534) tipc_recvmsg+0x3d7/0xe80 (net/tipc/socket.c:1934) io_recvmsg+0x47e/0xda0

Fix by changing min_t(int, ...) to min_t(size_t, ...) in both functions. The result is always <= (dlen - offset), which is bounded by TIPC maximum message size (0x1ffff bytes), so the implicit narrowing on assignment to int copy is always safe.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68289.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e9f8b10101c6da3ab000a2fb17162374c9bd2c69
Fixed
1b6066313b9b8fac870483bf7a26d6bd56579747
Fixed
7364014fdc289225229eb08de8bcbf4580e78e4d
Fixed
fe9bf32bb18f2d35789d4960fb007d1059bbaa38
Fixed
47f42ff521b4eeb46e82f9a46a4783a99f7570d7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68289.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.12.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68289.json"