CVE-2026-68289
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()
In tipc_recvmsg(), the copy length is computed as:
buflen is size_t but min_t(int, ...) casts it to int. When buflen exceeds INT_MAX (e.g. 0xFFFFFFFF via io_uring provided buffers), it wraps negative, wins the comparison, and the negative copy length propagates to simple_copy_to_iter() where int-to-size_t promotion makes it SIZE_MAX, triggering a WARN_ON. tipc_recvstream() has the same pattern.
Fix by changing min_t(int, ...) to min_t(size_t, ...) in both functions. The result is always <= (dlen - offset), which is bounded by TIPC maximum message size (0x1ffff bytes), so the implicit narrowing on assignment to int copy is always safe.
Technical details traces, logs and code from the original report
copy = min_t(int, dlen - offset, buflen); Kernel panic - not syncing: kernel: panic_on_warn set ... RIP: 0010:simple_copy_to_iter+0x9e/0xd0 (net/core/datagram.c:521) Call Trace: __skb_datagram_iter+0x123/0x8b0 (net/core/datagram.c:402) skb_copy_datagram_iter+0x77/0x1a0 (net/core/datagram.c:534) tipc_recvmsg+0x3d7/0xe80 (net/tipc/socket.c:1934) io_recvmsg+0x47e/0xda0
CVSS
NVD hasn't assigned a CVSS score to this CVE (common since the April 2026 policy change).
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.18%
- Percentile among all scored CVEs: 7
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
References
- https://git.kernel.org/stable/c/1b6066313b9b8fac870483bf7a26d6bd56579747
- https://git.kernel.org/stable/c/47f42ff521b4eeb46e82f9a46a4783a99f7570d7
- https://git.kernel.org/stable/c/7364014fdc289225229eb08de8bcbf4580e78e4d
- https://git.kernel.org/stable/c/93580911f02d1f4a506ec0a6fc4354140c53ffe8
- https://git.kernel.org/stable/c/9fd4f92671146b068809b6c34b50346cb30cf8f7
- https://git.kernel.org/stable/c/fe9bf32bb18f2d35789d4960fb007d1059bbaa38
Raw JSON (NVD)
Show
{
"id": "CVE-2026-68289",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "e9f8b10101c6da3ab000a2fb17162374c9bd2c69",
"lessThan": "9fd4f92671146b068809b6c34b50346cb30cf8f7",
"versionType": "git"
},
{
"status": "affected",
"version": "e9f8b10101c6da3ab000a2fb17162374c9bd2c69",
"lessThan": "93580911f02d1f4a506ec0a6fc4354140c53ffe8",
"versionType": "git"
},
{
"status": "affected",
"version": "e9f8b10101c6da3ab000a2fb17162374c9bd2c69",
"lessThan": "1b6066313b9b8fac870483bf7a26d6bd56579747",
"versionType": "git"
},
{
"status": "affected",
"version": "e9f8b10101c6da3ab000a2fb17162374c9bd2c69",
"lessThan": "7364014fdc289225229eb08de8bcbf4580e78e4d",
"versionType": "git"
},
{
"status": "affected",
"version": "e9f8b10101c6da3ab000a2fb17162374c9bd2c69",
"lessThan": "fe9bf32bb18f2d35789d4960fb007d1059bbaa38",
"versionType": "git"
},
{
"status": "affected",
"version": "e9f8b10101c6da3ab000a2fb17162374c9bd2c69",
"lessThan": "47f42ff521b4eeb46e82f9a46a4783a99f7570d7",
"versionType": "git"
}
],
"programFiles": [
"net/tipc/socket.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.12"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.12",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"net/tipc/socket.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-10T13:20:18.233",
"references": [
{
"url": "https://git.kernel.org/stable/c/1b6066313b9b8fac870483bf7a26d6bd56579747",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/47f42ff521b4eeb46e82f9a46a4783a99f7570d7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7364014fdc289225229eb08de8bcbf4580e78e4d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/93580911f02d1f4a506ec0a6fc4354140c53ffe8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9fd4f92671146b068809b6c34b50346cb30cf8f7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fe9bf32bb18f2d35789d4960fb007d1059bbaa38",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()\n\nIn tipc_recvmsg(), the copy length is computed as:\n\n copy = min_t(int, dlen - offset, buflen);\n\nbuflen is size_t but min_t(int, ...) casts it to int. When buflen\nexceeds INT_MAX (e.g. 0xFFFFFFFF via io_uring provided buffers), it\nwraps negative, wins the comparison, and the negative copy length\npropagates to simple_copy_to_iter() where int-to-size_t promotion\nmakes it SIZE_MAX, triggering a WARN_ON. tipc_recvstream() has the\nsame pattern.\n\n Kernel panic - not syncing: kernel: panic_on_warn set ...\n RIP: 0010:simple_copy_to_iter+0x9e/0xd0 (net/core/datagram.c:521)\n Call Trace:\n __skb_datagram_iter+0x123/0x8b0 (net/core/datagram.c:402)\n skb_copy_datagram_iter+0x77/0x1a0 (net/core/datagram.c:534)\n tipc_recvmsg+0x3d7/0xe80 (net/tipc/socket.c:1934)\n io_recvmsg+0x47e/0xda0\n\nFix by changing min_t(int, ...) to min_t(size_t, ...) in both\nfunctions. The result is always <= (dlen - offset), which is bounded\nby TIPC maximum message size (0x1ffff bytes), so the implicit\nnarrowing on assignment to int copy is always safe."
}
],
"lastModified": "2026-10-03T11:17:36.700",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}