Junglewise Threat Intelligence

CVE-2026-74281: Linux kernel TIPC memory leak from inverted service ranges

CVE-2026-74281 · Severity: high · CVSS 7.5 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's TIPC (Transparent Inter-Process Communication) subsystem fails to validate service range bounds advertised by peer nodes. A malicious or compromised peer can send specially crafted network messages with inverted service ranges (lower value greater than upper value) that get inserted into the kernel's binding table but can never be matched or withdrawn, causing unbounded memory leaks over the lifetime of the system.

Technical details

The vulnerability exists in tipc_update_nametbl() in net/tipc/name_distr.c, which processes PUBLICATION items received from peer nodes. Unlike the local bind path which validates service ranges via tipc_uaddr_valid(), the network processing path fails to check that lower <= upper. A binding with lower > upper is inserted at the far end of a red-black tree keyed on the lower bound, making it unreachable to any lookup or withdrawal operation (which require sr->lower <= end). This results in leaked publication entries, service_range nodes, and augmented rbtree entries for the lifetime of the namespace. Additionally, there is no per-peer cap equivalent to TIPC_MAX_PUBL on remotely learned bindings, allowing a peer to leak unbounded memory by sending malicious PUBLICATION items. The fix adds a bounds check before updating the name table. Network reachability to a TIPC peer is required; no authentication bypass or local privilege escalation is involved.

Affected products

  • Linux Linux kernel multiple versions before fix (commit 2afb648f7b99216c687db1f89739c995e1144153)

Timeline

  • 2026-08-15: disclosed: CVE-2026-74281 published
  • 2026-06-11: patched: Upstream patch merged (commit 2afb648f7b99216c687db1f89739c995e1144153)
  • 2026-07-24: patched: Backported to stable trees (commit 581ef56e5c34d475056ce086dc2ba0e872ba6857)

References

Related threats