Junglewise Threat Intelligence

CVE-2026-64450: Linux Kernel out-of-bounds read in TIPC broadcast Gap ACK blocks

CVE-2026-64450 · Severity: info · CVSS 6.5 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Transparent Inter-Process Communication (TIPC) protocol. TIPC is used for efficient communication between nodes in a cluster. An attacker on the same local network could send a specially crafted broadcast message that causes the system to read memory outside of the intended buffer. This could potentially lead to the exposure of sensitive kernel information or cause system instability.

Technical details

An out-of-bounds read exists in the TIPC protocol's broadcast synchronization logic. The function tipc_get_gap_ack_blks() fails to verify that a Gap ACK blocks record fits within the actual message data area (msg_data_sz) before it is processed. While unicast paths correctly bound this check, the broadcast path in tipc_bcast_sync_rcv() does not. An attacker can provide a large bgack_cnt in a short broadcast STATE_MSG, causing kmemdup() to read beyond the end of the allocated socket buffer (skb). This results in a slab-out-of-bounds read of up to 1024 bytes. The issue has been patched by adding proper bounds checking against msg_data_sz() in the broadcast receive path.

Affected products

  • Linux Linux Kernel All versions supporting TIPC Gap ACK blocks prior to the fix

Timeline

  • 2026-06-25: disclosed: Initial patch submission by Samuel Page
  • 2026-07-24: patched: Patch committed to stable kernel tree
  • 2026-07-25: advisory: CVE-2026-64450 published

References

Related threats