All findings

CVE-2026-64450 medium

BynarIO maps a Linux TIPC broadcast parser flaw to CVE-2026-64450

BynarIO says its AI research found an out-of-bounds read in Linux TIPC broadcast Gap ACK handling, fixed upstream as CVE-2026-64450.

Bug class
Out-of-bounds read in broadcast Gap ACK block parsing
Affected codebase
Linux kernel TIPC
Credited system
BynarIO AI
Disclosed
July 25, 2026
Attribution
Self-reported attribution
Severity
medium
Source status: The public Linux CVE and fix corroborate the vulnerability. Bynario supplies the AI-discovery attribution. Bugflation follows Red Hat's CVSS 5.5 product assessment rather than the higher generic CNA score.

Summary

Malformed TIPC Gap ACK blocks could drive the broadcast receive path beyond the valid block array. The bug was accepted and fixed upstream. Because the upstream record does not name BynarIO AI, the discovery attribution remains self-reported.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.