CVE-2026-31662: tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG

Published Apr 24, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

tipc: fix bcackers underflow on duplicate GRPACKMSG

The GRPACKMSG handler in tipcgroupprotorcv() currently decrements bcackers on every inbound group ACK, even when the same member has already acknowledged the current broadcast round.

Because bcackers is a u16, a duplicate ACK received after the last legitimate ACK wraps the counter to 65535. Once wrapped, tipcgroupbccong() keeps reporting congestion and later group broadcasts on the affected socket stay blocked until the group is recreated.

Fix this by ignoring duplicate or stale ACKs before touching bcacked or bcackers. This makes repeated GRPACKMSG handling idempotent and prevents the underflow path.

Affected Software

17 affected componentsFixes available
Linux Linux kernel
Linux Linux kernel>=4.15.1<5.10.253
Linux Linux kernel>=5.11<5.15.203
Linux Linux kernel>=5.16<6.1.169
Linux Linux kernel>=6.2<6.6.135
Linux Linux kernel>=6.7<6.12.82
Linux Linux kernel>=6.13<6.18.23
Linux Linux kernel>=6.19<6.19.13
Linux Linux kernel=4.15
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Linux Linux kernel=7.0-rc7
Microsoft azl3 kernel 6.6.134.1-2

Event History

Apr 24, 2026
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionSeverity
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 26, 2026
Data Sourced
via Microsoft·08:06 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:06 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2026-31662?

CVE-2026-31662 is classified as a low-severity vulnerability affecting the Linux kernel.

2

How do I fix CVE-2026-31662?

To address CVE-2026-31662, update your Linux kernel to a patched version provided by your distribution.

3

What systems are affected by CVE-2026-31662?

CVE-2026-31662 affects the Linux kernel, specifically versions prior to the fix for the tipc_group_proto_rcv function.

4

What type of vulnerability is CVE-2026-31662?

CVE-2026-31662 is a programming error vulnerability that involves an underflow in the processing of duplicate group acknowledgment messages.

5

Is there any exploit available for CVE-2026-31662?

There are currently no known exploits for CVE-2026-31662 in the wild, but it is still advisable to apply the fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203