SB20260815196 - Improper access control in Linux kernel tipc
Published: August 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-74283)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to modify TIPC state.
The vulnerability exists due to improper access control in TIPCv2 generic-netlink mutator operations when handling netlink administrative commands. A local user can invoke mutating netlink operations to modify TIPC state.
The issue affects commands that can change the network id and node identity, set or flush key material, and enable or disable a UDP bearer.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/52864c6c13dcc292481eabfeb3c31a86c3ec06f2
- https://git.kernel.org/stable/c/56f0a2e0a1d004e025cd031c3a801ab73959269f
- https://git.kernel.org/stable/c/86b0c540e2ea397cde021eecd24145f7c16a3d4e
- https://git.kernel.org/stable/c/9b937de4b3ded62a24da6e8d9d623cdb2748fa74
- https://git.kernel.org/stable/c/b06fb5f78a9af0929aaa47c92d0b7bca0617fb25
- https://git.kernel.org/stable/c/c9668a4adb2264625daeeabc7466b783badd4614
- https://git.kernel.org/stable/c/cebaefe1aceb650d5c99a4c0e1a4dde09e211818
- https://git.kernel.org/stable/c/e87dcc1a644d087de0bb6c94c6dd28c29b89597f