Answer in brief
CVE-2026-74281 records a Unknown severity vulnerability in tipc: reject inverted service ranges from peer bindings. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-74281 records a Unknown severity vulnerability in tipc: reject inverted service ranges from peer bindings. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=37922ea4a3105176357c8d565a9d982c4a08714a <cd1955f81bd8ebeef51b324989ac871ad1947fb6 || >=37922ea4a3105176357c8d565a9d982c4a08714a <f683200b83a0085d4e11abea8c1fdd9fdfb95b0b || >=37922ea4a3105176357c8d565a9d982c4a08714a <f1715d92ee3095d9215b493a8603a81f646fcf61 || >=37922ea4a3105176357c8d565a9d982c4a08714a <581ef56e5c34d475056ce086dc2ba0e872ba6857 || >=37922ea4a3105176357c8d565a9d982c4a08714a <7e401233f9bb74a626e70698d0d62f3a94ac0676 || >=37922ea4a3105176357c8d565a9d982c4a08714a <973bf0ed896b9898668dbadb82ed849d7d573010 || >=37922ea4a3105176357c8d565a9d982c4a08714a <2afb648f7b99216c687db1f89739c995e1144153 | cd1955f81bd8ebeef51b324989ac871ad1947fb6, f683200b83a0085d4e11abea8c1fdd9fdfb95b0b, f1715d92ee3095d9215b493a8603a81f646fcf61, 581ef56e5c34d475056ce086dc2ba0e872ba6857, 7e401233f9bb74a626e70698d0d62f3a94ac0676, 973bf0ed896b9898668dbadb82ed849d7d573010, 2afb648f7b99216c687db1f89739c995e1144153 |
| Linux/Linuxgeneric | 4.17 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: tipc: reject inverted service ranges from peer bindings tipc_update_nametbl() inserts a binding advertised by a peer node using the lower and upper service-range bounds taken directly from the wire, without checking that lower <= upper. The local bind path validates the ordering (tipc_uaddr_valid()), but the name-distribution path does not. A binding with lower > upper is inserted at the far end of the service-range rbtree (keyed on lower) where no lookup or withdrawal can ever match it (service_range_foreach_match() requires sr->lower <= end). The publication, its service_range node and the augmented rbtree entry are then leaked for the lifetime of the namespace, and there is no per-peer cap equivalent to TIPC_MAX_PUBL on locally created bindings. Reject inverted ranges in the network path as well. A peer node can otherwise leak unbounded binding-table memory by sending PUBLICATION items with lower > upper.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=37922ea4a3105176357c8d565a9d982c4a08714a <cd1955f81bd8ebeef51b324989ac871ad1947fb6 || >=37922ea4a3105176357c8d565a9d982c4a08714a <f683200b83a0085d4e11abea8c1fdd9fdfb95b0b || >=37922ea4a3105176357c8d565a9d982c4a08714a <f1715d92ee3095d9215b493a8603a81f646fcf61 || >=37922ea4a3105176357c8d565a9d982c4a08714a <581ef56e5c34d475056ce086dc2ba0e872ba6857 || >=37922ea4a3105176357c8d565a9d982c4a08714a <7e401233f9bb74a626e70698d0d62f3a94ac0676 || >=37922ea4a3105176357c8d565a9d982c4a08714a <973bf0ed896b9898668dbadb82ed849d7d573010 || >=37922ea4a3105176357c8d565a9d982c4a08714a <2afb648f7b99216c687db1f89739c995e1144153 | cd1955f81bd8ebeef51b324989ac871ad1947fb6, f683200b83a0085d4e11abea8c1fdd9fdfb95b0b, f1715d92ee3095d9215b493a8603a81f646fcf61, 581ef56e5c34d475056ce086dc2ba0e872ba6857, 7e401233f9bb74a626e70698d0d62f3a94ac0676, 973bf0ed896b9898668dbadb82ed849d7d573010, 2afb648f7b99216c687db1f89739c995e1144153 |
| Linux/Linuxgeneric | 4.17 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: tipc: reject inverted service ranges from peer bindings tipc_update_nametbl() inserts a binding advertised by a peer node using the lower and upper service-range bounds taken directly from the wire, without checking that lower <= upper. The local bind path validates the ordering (tipc_uaddr_valid()), but the name-distribution path does not. A binding with lower > upper is inserted at the far end of the service-range rbtree (keyed on lower) where no lookup or withdrawal can ever match it (service_range_foreach_match() requires sr->lower <= end). The publication, its service_range node and the augmented rbtree entry are then leaked for the lifetime of the namespace, and there is no per-peer cap equivalent to TIPC_MAX_PUBL on locally created bindings. Reject inverted ranges in the network path as well. A peer node can otherwise leak unbounded binding-table memory by sending PUBLICATION items with lower > upper.
Quoted source text, attributed separately from HOL analysis.