1sealsemantic last-mile verification

Research / Finding

tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG

F-TORVALDS-LINUX-TIPC-001

Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

—score not recorded
CVE-2026-31662CVEtorvalds/linux

tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG

Fixed in: Linux kernel upstream

patched
details
Finding IDs
F-TORVALDS-LINUX-TIPC-001
CVE
CVE-2026-31662
GHSA
GHSA-895h-4xx6-r95p
Status
patched
Fixed in
Linux kernel upstream
Note
GHSA-895h-4xx6-r95p · Red Hat also tracks this as a kernel CVE · Linux CNA/GHSA credit fields are empty; credit is carried by upstream patch artifacts (Author/Signed-off-by)
CVE registry state
PUBLISHED
CVE state checked

F-TORVALDS-LINUX-TIPC-001: Input / state handling. Duplicate acknowledgements underflow bc_ackers and block later broadcasts; no memory corruption is asserted. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-TORVALDS-LINUX-TIPC-001

Security area (1seal assessment): Availability. Duplicate acknowledgements underflow bc_ackers and block later broadcasts; no memory corruption is asserted. Reviewed 24 Sep 2026.

—score not recorded
torvalds/linuxReported fixtorvalds/linux

tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG

merged
details
Finding IDs
F-TORVALDS-LINUX-TIPC-001
Status
merged
Reported via
netdev maintainers
Note
accepted upstream in netdev/net: 48a5fe38772b. duplicate or stale GRP_ACK_MSG packets could underflow bc_ackers, wrap to 65535, and leave later group broadcasts congestion-blocked until the group was recreated. stable backports are queued for 5.10-stable, 5.15-stable, 6.1-stable, and 6.6-stable.

F-TORVALDS-LINUX-TIPC-001: Input / state handling. Duplicate acknowledgements underflow bc_ackers and block later broadcasts; no memory corruption is asserted. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-TORVALDS-LINUX-TIPC-001

Security area (1seal assessment): Availability. Duplicate acknowledgements underflow bc_ackers and block later broadcasts; no memory corruption is asserted. Reviewed 24 Sep 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.