SB20260815196 - Improper access control in Linux kernel tipc



SB20260815196 - Improper access control in Linux kernel tipc

Published: August 15, 2026

Security Bulletin ID SB20260815196
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2026-74283)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to modify TIPC state.

The vulnerability exists due to improper access control in TIPCv2 generic-netlink mutator operations when handling netlink administrative commands. A local user can invoke mutating netlink operations to modify TIPC state.

The issue affects commands that can change the network id and node identity, set or flush key material, and enable or disable a UDP bearer.


Remediation

Install update from vendor's website.