cbcvebase.
CVE-2026-31635
published 2026-04-24

CVE-2026-31635: In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix oversized RESPONSE authenticator length check rxgk_verify_response() decodes…

PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.82%
53.6th percentile
In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix oversized RESPONSE authenticator length check rxgk_verify_response() decodes auth_len from the packet and is supposed to verify that it fits in the remaining bytes. The existing check is inverted, so oversized RESPONSE authenticators are accepted and passed to rxgk_decrypt_skb(), which can later reach skb_to_sgvec() with an impossible length and hit BUG_ON(len). Decoded from the original latest-net reproduction logs with scripts/decode_stacktrace.sh: RIP: __skb_to_sgvec() [net/core/skbuff.c:5285 (discriminator 1)] Call Trace: skb_to_sgvec() [net/core/skbuff.c:5305] rxgk_decrypt_skb() [net/rxrpc/rxgk_common.h:81] rxgk_verify_response() [net/rxrpc/rxgk.c:1268] rxrpc_process_connection() [net/rxrpc/conn_event.c:266 net/rxrpc/conn_event.c:364 net/rxrpc/conn_event.c:386] process_one_work() [kernel/workqueue.c:3281] worker_thread() [kernel/workqueue.c:3353 kernel/workqueue.c:3440] kthread() [kernel/kthread.c:436] ret_from_fork() [arch/x86/kernel/process.c:164] Reject authenticator lengths that exceed the remaining packet payload.

Affected

16 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a < beee051f259acd286fed64c32c2b31e6f5097eb5beee051f259acd286fed64c32c2b31e6f5097eb5
linuxlinux>= 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a < e2f1a80d8b1ed6a5ae585a399c2b46500bdcc305e2f1a80d8b1ed6a5ae585a399c2b46500bdcc305
linuxlinux>= 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a < a2567217ade970ecc458144b6be469bc015b23e5a2567217ade970ecc458144b6be469bc015b23e5
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 6.16.1 < 6.18.236.18.23
linuxlinux_kernel>= 6.19 < 6.19.136.19.13
ubuntulinux
ubuntulinux-azure-6.17
ubuntulinux-azure-fde-6.17
ubuntulinux-hwe-6.17
ubuntulinux-nvidia-6.17
ubuntulinux-oem-6.17
ubuntulinux-raspi

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu7.1HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.