PT-2026-98761 · Linux · Linux
CVE-2026-98098
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix NULL deref in tipc named node up() on empty publication list
User-space applications can bind a large number of service addresses to
one or more sockets. Each binding of a local-scope service address inserts
one entry (publication) into the TIPC name table. If the number of these
publications exceeds TIPC MAX PUBL (65535), protocol service types
(such as node state and link state) are no longer inserted into the name
table. This causes two issues:
-
User-space applications subscribing to node or link up/down events stop receiving notifications.
-
A NULL pointer dereference can occur:
BUG: kernel NULL pointer dereference, address: 00000000000000d0
...
CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 7.2.0-rc4-default+ #5 PREEMPT(full)
...
RIP: 0010:tipc named node up (./include/linux/skbuff.h:2251 net/tipc/name distr.c:195 net/tipc/name distr.c:221)
...
Call Trace:
tipc node write unlock (net/tipc/node.c:428)
tipc rcv (net/tipc/node.c:934 net/tipc/node.c:2189)
tipc udp recv (net/tipc/udp media.c:389)
| Thread 1 (tipc net finalize) | Thread 2 (named distribute) |
|---|
| ...
| list for each entry(publ, pls, binding node) {
| ...
| skb queue tail(list, skb);
| ...
| }
| ...
| hdr = buf msg(skb peek tail(list));... |
tipc nametbl publish(); |
If 'tipc nametbl publish()' (Thread 1) fails because the number of
local publications reaches TIPC MAX PUBL, list (Thread 2) will be empty. As a
result, NULL is passed to 'buf msg()', leading to a NULL pointer dereference.
Fix these issues by allowing protocol service types (node state, link state,
and topology server) to be inserted into the name table unconditionally.
This ensures that users subscribing to these types always receive
notifications. In addition, the maximum number of local user publications is
reduced to (TIPC MAX PUBL - 1). This ensures that the maximum bulk size
calculated in tipc link set queue limits() remains valid.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux