CVE-2026-43411: tipc: fix divide-by-zero in tipc_sk_filter_connect()
In the Linux kernel, the following vulnerability has been resolved:
tipc: fix divide-by-zero in tipcskfilterconnect()
A user can set conntimeout to any value via setsockopt(TIPCCONNTIMEOUT), including values less than 4. When a SYN is rejected with TIPCERROVERLOAD and the retry path in tipcskfilterconnect() executes:
delay %= (tsk->conntimeout / 4);
If conntimeout is in the range [0, 3], the integer division yields 0, and the modulo operation triggers a divide-by-zero exception, causing a kernel oops/panic.
Fix this by clamping conntimeout to a minimum of 4 at the point of use in tipcskfilterconnect().
Oops: divide error: 0000 [#1] SMP KASAN NOPTI CPU: 0 UID: 0 PID: 119 Comm: poc-F144 Not tainted 7.0.0-rc2+ RIP: 0010:tipcskfilterrcv (net/tipc/socket.c:2236 net/tipc/socket.c:2362) Call Trace: tipcskbacklogrcv (include/linux/instrumented.h:82 include/linux/atomic/atomic-instrumented.h:32 include/net/sock.h:2357 net/tipc/socket.c:2406) releasesock (include/net/sock.h:1185 net/core/sock.c:3213) releasesock (net/core/sock.c:3797) tipcconnect (net/tipc/socket.c:2570) sysconnect (include/linux/file.h:62 include/linux/file.h:83 net/socket.c:2098)