CVE-2026-68323: tipc: serialize udp bearer replicast list updates
In the Linux kernel, the following vulnerability has been resolved:
tipc: serialize udp bearer replicast list updates
tipcudprcastadd() and cleanupbearer() both update ub->rcast.list with listaddrcu() / listdelrcu(), but nothing serializes them. The add runs from the encap receive softirq (via tipcudprcastdisc()) without rtnllock(), so it can race the cleanup delete and corrupt the list:
listdel corruption. prev->next should be ffff8880298d7ab8, but was ffff88802449ad38. (prev=ffff888027e3ec98) kernel BUG at lib/listdebug.c:62! RIP: listdelentryvalidorreport+0x17a/0x200 Workqueue: events cleanupbearer Call Trace: cleanupbearer (net/tipc/udpmedia.c:811) processonework (kernel/workqueue.c:3302) workerthread (kernel/workqueue.c:3466)
The bearer can be enabled from an unprivileged user namespace, as the TIPCv2 generic-netlink ops carry no GENLADMINPERM.
Add a spinlock to struct udpbearer and take it around the listaddrcu() in tipcudprcastadd() and the listdelrcu() loop in cleanupbearer() so the two writers can no longer corrupt the list.
Reject a duplicate peer under the same lock before allocating, and remove tipcudpisknownpeer(). The old lockless pre-check in tipcudprcastdisc() was racy: two softirqs discovering the same peer could both find it absent and add it twice.
cleanupbearer() runs from a workqueue after tipcudpdisable() clears the bearer's up bit, so an encap softirq can still reach tipcudprcastadd() and add a peer after cleanupbearer() has already emptied the list, leaking that entry when the bearer is freed. Mark the bearer disabled under rcastlock once the list is emptied and refuse further additions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68323?
The severity of CVE-2026-68323 is rated at 55, indicating a moderate risk level.
How do I fix CVE-2026-68323?
To fix CVE-2026-68323, update your Linux kernel to the latest patched version that addresses this vulnerability.
What impact does CVE-2026-68323 have on system security?
CVE-2026-68323 could potentially allow unauthorized access or manipulation of the udp bearer replicast list, affecting system stability and security.
Is CVE-2026-68323 exploitable remotely?
Yes, CVE-2026-68323 can be exploited remotely if specific conditions are met, exposing systems to risks associated with untrusted UDP packets.
Which systems are affected by CVE-2026-68323?
CVE-2026-68323 affects all systems running vulnerable versions of the Linux kernel that utilize the TIPC protocol.