cbcvebase.
CVE-2026-45988
published 2026-05-27

CVE-2026-45988: In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix re-decryption of RESPONSE packets If a RESPONSE packet gets a temporary failure…

PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.46%
37.3th percentile
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix re-decryption of RESPONSE packets If a RESPONSE packet gets a temporary failure during processing, it may end up in a partially decrypted state - and then get requeued for a retry. Fix this by just discarding the packet; we will send another CHALLENGE packet and thereby elicit a further response. Similarly, discard an incoming CHALLENGE packet if we get an error whilst generating a RESPONSE; the server will send another CHALLENGE.

Affected

75 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 17926a79320afa9b95df6b977b40cca6d8713cea < d61482be4aae1835b78875761206241835a7510ed61482be4aae1835b78875761206241835a7510e
linuxlinux>= 17926a79320afa9b95df6b977b40cca6d8713cea < 7b89868305052b94a91b708c462bc2281fa42a4a7b89868305052b94a91b708c462bc2281fa42a4a
linuxlinux>= 17926a79320afa9b95df6b977b40cca6d8713cea < 76cb9a2d252274adfae6e293a292434631a7d47276cb9a2d252274adfae6e293a292434631a7d472
linuxlinux>= 17926a79320afa9b95df6b977b40cca6d8713cea < f55b383070170e988e4dec28be2af1714d258521f55b383070170e988e4dec28be2af1714d258521
linuxlinux>= 17926a79320afa9b95df6b977b40cca6d8713cea < 0422e7a4883f25101903f3e8105c0808aa5f4ce90422e7a4883f25101903f3e8105c0808aa5f4ce9
linuxlinux_kernel
linuxlinux_kernel>= 2.6.22 < 6.6.1406.6.140
linuxlinux_kernel>= 6.13 < 6.18.276.18.27
linuxlinux_kernel>= 6.19 < 7.0.47.0.4
linuxlinux_kernel>= 6.7 < 6.12.866.12.86
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-5.4
ubuntulinux-aws-6.8
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-4.15
ubuntulinux-azure-5.15
ubuntulinux-azure-5.4
ubuntulinux-azure-6.17
ubuntulinux-azure-6.8
ubuntulinux-azure-fde
ubuntulinux-azure-fde-5.15

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.