{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()  In tipc_recvmsg(), the copy length is computed as:    copy = min_t(int, dlen - offset, buflen);  buflen is size_t but min_t(int, ...) casts it to int. When buflen exceeds INT_MAX (e.g. 0xFFFFFFFF via io_uring provided buffers), it wraps negative, wins the comparison, and the negative copy length propagates to simple_copy_to_iter() where int-to-size_t promotion makes it SIZE_MAX, triggering a WARN_ON. tipc_recvstream() has the same pattern.    Kernel panic - not syncing: kernel: panic_on_warn set ...   RIP: 0010:simple_copy_to_iter+0x9e/0xd0 (net/core/datagram.c:521)   Call Trace:    __skb_datagram_iter+0x123/0x8b0 (net/core/datagram.c:402)    skb_copy_datagram_iter+0x77/0x1a0 (net/core/datagram.c:534)    tipc_recvmsg+0x3d7/0xe80 (net/tipc/socket.c:1934)    io_recvmsg+0x47e/0xda0  Fix by changing min_t(int, ...) to min_t(size_t, ...) in both functions. The result is always \u003c= (dlen - offset), which is bounded by TIPC maximum message size (0x1ffff bytes), so the implicit narrowing on assignment to int copy is always safe.",
  "id": "DEBIAN-CVE-2026-68289",
  "modified": "2026-09-14T16:47:49.589057699Z",
  "published": "2026-08-10T13:20:18.233Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-68289"
    }
  ],
  "upstream": [
    "CVE-2026-68289"
  ]
}