Impact
In the Linux kernel, TIPC’s group broadcast acknowledgment handling incorrectly decrements a 16‑bit counter for every received ACK. Duplicate ACKs after the final legitimate one wrap the counter to 65535, causing the module to report persistent congestion and permanently blocking subsequent broadcasts on the affected socket. This integer underflow (CWE‑191) results in a denial‑of‑service condition affecting TIPC group communications.
Affected Systems
Vulnerable kernel releases include Linux kernel 4.15 and every 7.0 release candidate from rc1 through rc7, as identified by the affected CPE strings. All distributions shipping one of these kernel versions could be impacted until the patch is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to inject or replay duplicate GRP_ACK_MSGs to a TIPC group, which is likely limited to a local or privileged network context; based on the description, the attack vector is inferred to be local or network, not remote code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA