CVE-2026-31633
published 2026-04-24CVE-2026-31633: In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix integer overflow in rxgk_verify_response() In rxgk_verify_response(), there's a…
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.47%
38.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Fix integer overflow in rxgk_verify_response()
In rxgk_verify_response(), there's a potential integer overflow due to
rounding up token_len before checking it, thereby allowing the length check to
be bypassed.
Fix this by checking the unrounded value against len too (len is limited as
the response must fit in a single UDP packet).
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a < 1f864d9daaf622aeaa774404fd51e7d6a435b046 | 1f864d9daaf622aeaa774404fd51e7d6a435b046 |
| linux | linux | >= 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a < c1e242beb6b1efc3c286f617e8d940c8fbf2ed41 | c1e242beb6b1efc3c286f617e8d940c8fbf2ed41 |
| linux | linux | >= 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a < 699e52180f4231c257821c037ed5c99d5eb0edb8 | 699e52180f4231c257821c037ed5c99d5eb0edb8 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 6.16.1 < 6.18.23 | 6.18.23 |
| linux | linux_kernel | >= 6.19 < 6.19.13 | 6.19.13 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: rxrpc: Fix integer overflow in rxgk_verify_response()
vendor_redhat·2026-04-24·CVSS 7.0
CVE-2026-31633 [MEDIUM] CWE-190 kernel: rxrpc: Fix integer overflow in rxgk_verify_response()
kernel: rxrpc: Fix integer overflow in rxgk_verify_response()
A flaw was found in the Linux kernel's rxrpc component. A potential integer overflow vulnerability exists in the `rxgk_verify_response()` function. This occurs when the `token_len` value is rounded up before a critical length check, allowing the check to be bypassed. This could potentially lead to unexpected behavior or resource exhaustion, as the response is intended to fit within a single User Datagram Protocol (UDP) packet.
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
GHSA
GHSA-5j64-84jf-59q3: In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Fix integer overflow in rxgk_verify_response()
In rxgk_verify_response(),
ghsa_unreviewed·2026-04-24
CVE-2026-31633 GHSA-5j64-84jf-59q3: In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Fix integer overflow in rxgk_verify_response()
In rxgk_verify_response(),
In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Fix integer overflow in rxgk_verify_response()
In rxgk_verify_response(), there's a potential integer overflow due to
rounding up token_len before checking it, thereby allowing the length check to
be bypassed.
Fix this by checking the unrounded value against len too (len is limited as
the response must fit in a single UDP packet).
No detection rules found.
No public exploits indexed.
2026-04-24
Published