CVE-2026-68297

HIGHPre-NVD 7.87.8
EchelonGraph scoreHIGH confidence

Score 7.8 from GitHub Security Advisory (severity: HIGH) published 2026-08-10. a secondary CVSS source baseline 7.8; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, secondary
Trending — 4 sources updated this week
7.8EG
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: 0%CVSS: 7.8Exploit: None knownExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

In the Linux kernel, the following vulnerability has been resolved:

tipc: fix u16 MTU truncation in media and bearer MTU validation

Both TIPC_NL_MEDIA_SET and TIPC_NL_BEARER_SET accept user-supplied MTU values but only enforce a minimum bound, not a maximum. When a user sets the MTU to a value exceeding U16_MAX (65535), it passes validation but is silently truncated when assigned to u16 fields l->mtu and l->advertised_mtu in tipc_link_create(). Values like 65536 (0x10000) truncate to 0, causing a division by zero in tipc_link_set_queue_limits() which computes TIPC_MAX_PUBL / (l->mtu / ITEM_SIZE). Other overflowing values (e.g. 65537-131071) produce small incorrect MTU values, resulting in link malfunction behaviors.

Crash stack (triggered as unprivileged user via user namespace):

tipc_link_set_queue_limits net/tipc/link.c:2531 tipc_link_create net/tipc/link.c:520 tipc_node_check_dest net/tipc/node.c:1279 tipc_disc_rcv net/tipc/discover.c:252 tipc_rcv net/tipc/node.c:2129 tipc_udp_recv net/tipc/udp_media.c:392

Two independent paths lack the upper bound check:

  • tipc_udp_mtu_bad() -- called from __tipc_nl_media_set() (MEDIA_SET)
  • inline check in __tipc_nl_bearer_set() at bearer.c:1160 (BEARER_SET)

Fix both by rejecting MTU values above U16_MAX.

CVSS v3
7.8
EG Score
7.8(high)
EG Risk
40(Track)
EG Risk 40/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity78% × 45%
Exploitation0% × 40%
Automatability30% × 15%
Action: Routine — remediate on your standard cadence.
EPSS PROB
0%
EPSS %ILE
3%
KEV
Not listed

Published

August 10, 2026

Last Modified

August 19, 2026

Advisory Details (5)

Auto-updated Aug 14, 2026
No patch confirmed yet.
generic

tipc: fix u16 MTU truncation in media and bearer MTU validation - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/f4013598b69457dbea350df52e52daea6faef8eb
generic

tipc: fix u16 MTU truncation in media and bearer MTU validation - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/f02334a9e378f7e07232b26dc3d2ab353339f040
generic

tipc: fix u16 MTU truncation in media and bearer MTU validation - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/c1cda72f6acec02ebd45d913bf8527ff77336ba6
generic

tipc: fix u16 MTU truncation in media and bearer MTU validation - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/9f29cd8a8e7901a2617c8064ce9f50fc67b97cb8
generic

tipc: fix u16 MTU truncation in media and bearer MTU validation - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/1b8fb5a20508bfb0db854e01214888c761b3a911

Vendor Advisories for CVE-2026-68297(2)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Data Freshness Timeline

(refreshed 37× in last 7d / 49× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-08-21 03:43 UTCEG score recompute
  2. 2026-08-21 03:43 UTCVendor advisory
  3. 2026-08-21 03:43 UTCGHSA enrichment
  4. 2026-08-20 22:56 UTCEPSS rescore
  5. 2026-08-20 16:17 UTCGHSA enrichment
  6. 2026-08-20 04:51 UTCGHSA enrichment
  7. 2026-08-19 17:25 UTCEG score recompute
  8. 2026-08-19 17:25 UTCGHSA enrichment
  9. 2026-08-19 17:04 UTCEPSS rescore
  10. 2026-08-19 16:54 UTCEG score recompute
  11. 2026-08-19 16:54 UTCGHSA enrichment
  12. 2026-08-19 14:49 UTCGHSA enrichment
  13. 2026-08-19 03:24 UTCGHSA enrichment
  14. 2026-08-18 15:58 UTCEG score recompute
  15. 2026-08-18 15:58 UTCGHSA enrichment
  16. 2026-08-18 13:49 UTCEPSS rescore
  17. 2026-08-18 13:49 UTCEPSS rescore
  18. 2026-08-18 04:29 UTCGHSA enrichment
  19. 2026-08-17 17:03 UTCEG score recompute
  20. 2026-08-17 17:03 UTCGHSA enrichment
  21. 2026-08-17 13:47 UTCEPSS rescore
  22. 2026-08-17 05:37 UTCEG score recompute
  23. 2026-08-17 05:37 UTCGHSA enrichment
  24. 2026-08-17 05:06 UTCEG score recompute
  25. 2026-08-17 05:06 UTCGHSA enrichment
Show 24 more
  1. 2026-08-16 20:22 UTCEG score recompute
  2. 2026-08-16 20:22 UTCGHSA enrichment
  3. 2026-08-16 14:56 UTCEPSS rescore
  4. 2026-08-16 08:56 UTCEG score recompute
  5. 2026-08-16 08:56 UTCGHSA enrichment
  6. 2026-08-15 21:30 UTCGHSA enrichment
  7. 2026-08-15 10:04 UTCEG score recompute
  8. 2026-08-15 10:04 UTCGHSA enrichment
  9. 2026-08-15 01:30 UTCEPSS rescore
  10. 2026-08-14 22:38 UTCGHSA enrichment
  11. 2026-08-14 11:12 UTCEG score recompute
  12. 2026-08-14 11:12 UTCGHSA enrichment
  13. 2026-08-13 23:46 UTCEG score recompute
  14. 2026-08-13 23:46 UTCGHSA enrichment
  15. 2026-08-13 22:44 UTCEG score recompute 7.80
  16. 2026-08-13 22:44 UTCGHSA enrichment
  17. 2026-08-13 22:44 UTCMITRE cvelistV5CVSS v3 → 7.8 · severity → HIGH
  18. 2026-08-13 22:00 UTCEPSS rescore
  19. 2026-08-13 14:38 UTCEG score recompute
  20. 2026-08-13 14:38 UTCGHSA enrichment
  21. 2026-08-12 13:51 UTCEPSS rescore
  22. 2026-08-10 13:24 UTCNVD update
  23. 2026-08-10 12:19 UTCEG score recompute
  24. 2026-08-10 12:17 UTCMITRE cvelistV5first tracked

Frequently asked(5)

What is CVE-2026-68297?
CVE-2026-68297 is a high vulnerability published on August 10, 2026. In the Linux kernel, the following vulnerability has been resolved: tipc: fix u16 MTU truncation in media and bearer MTU validation Both TIPCNLMEDIASET and TIPCNLBEARERSET accept user-supplied MTU values but only enforce a minimum bound, not a maximum. When a user sets the MTU to a value exceeding…
When was CVE-2026-68297 disclosed?
CVE-2026-68297 was first published in the National Vulnerability Database on August 10, 2026, with the most recent update on August 19, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-68297 actively exploited?
CVE-2026-68297 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0% probability of exploitation in the next 30 days, which ranks it in the top 97.0% of all scored CVEs.
What is the CVSS score of CVE-2026-68297?
CVE-2026-68297 has a CVSS v3 base score of 7.8 (NVD).
How do I remediate CVE-2026-68297?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-68297, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-68297

Explore →

Is Your Infrastructure Affected by CVE-2026-68297?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.