PT-2026-98761 · Linux · Linux

CVE-2026-98098

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix NULL deref in tipc named node up() on empty publication list
User-space applications can bind a large number of service addresses to one or more sockets. Each binding of a local-scope service address inserts one entry (publication) into the TIPC name table. If the number of these publications exceeds TIPC MAX PUBL (65535), protocol service types (such as node state and link state) are no longer inserted into the name table. This causes two issues:
  1. User-space applications subscribing to node or link up/down events stop receiving notifications.
  2. A NULL pointer dereference can occur:
BUG: kernel NULL pointer dereference, address: 00000000000000d0 ... CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 7.2.0-rc4-default+ #5 PREEMPT(full) ... RIP: 0010:tipc named node up (./include/linux/skbuff.h:2251 net/tipc/name distr.c:195 net/tipc/name distr.c:221) ... Call Trace: tipc node write unlock (net/tipc/node.c:428) tipc rcv (net/tipc/node.c:934 net/tipc/node.c:2189) tipc udp recv (net/tipc/udp media.c:389)
Thread 1 (tipc net finalize)Thread 2 (named distribute)
            | ...
            | list for each entry(publ, pls, binding node) {
            | ...
            |  skb queue tail(list, skb);
            | ...
            | }
            | ...
            | hdr = buf msg(skb peek tail(list));
... | tipc nametbl publish(); |
If 'tipc nametbl publish()' (Thread 1) fails because the number of local publications reaches TIPC MAX PUBL, list (Thread 2) will be empty. As a result, NULL is passed to 'buf msg()', leading to a NULL pointer dereference.
Fix these issues by allowing protocol service types (node state, link state, and topology server) to be inserted into the name table unconditionally. This ensures that users subscribing to these types always receive notifications. In addition, the maximum number of local user publications is reduced to (TIPC MAX PUBL - 1). This ensures that the maximum bulk size calculated in tipc link set queue limits() remains valid.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98098

Affected Products

Linux