tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG
Fixed in: Linux kernel upstream
patched
details
Finding IDs
F-TORVALDS-LINUX-TIPC-001
CVE
CVE-2026-31662
GHSA
GHSA-895h-4xx6-r95p
Status
patched
Fixed in
Linux kernel upstream
Note
GHSA-895h-4xx6-r95p · Red Hat also tracks this as a kernel CVE · Linux CNA/GHSA credit fields are empty; credit is carried by upstream patch artifacts (Author/Signed-off-by)
CVE registry state
PUBLISHED
CVE state checked
F-TORVALDS-LINUX-TIPC-001: Input / state handling. Duplicate acknowledgements underflow bc_ackers and block later broadcasts; no memory corruption is asserted. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Security area (1seal assessment): Availability. Duplicate acknowledgements underflow bc_ackers and block later broadcasts; no memory corruption is asserted. Reviewed 24 Sep 2026.
tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG
merged
details
Finding IDs
F-TORVALDS-LINUX-TIPC-001
Status
merged
Reported via
netdev maintainers
Note
accepted upstream in netdev/net: 48a5fe38772b. duplicate or stale GRP_ACK_MSG packets could underflow bc_ackers, wrap to 65535, and leave later group broadcasts congestion-blocked until the group was recreated. stable backports are queued for 5.10-stable, 5.15-stable, 6.1-stable, and 6.6-stable.
F-TORVALDS-LINUX-TIPC-001: Input / state handling. Duplicate acknowledgements underflow bc_ackers and block later broadcasts; no memory corruption is asserted. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Security area (1seal assessment): Availability. Duplicate acknowledgements underflow bc_ackers and block later broadcasts; no memory corruption is asserted. Reviewed 24 Sep 2026.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.