Executive brief
A vulnerability in the Linux kernel's networking subsystem could allow a remote attacker to disrupt system operations. The issue exists in the RxRPC protocol implementation, which is used for certain types of network communications. By sending specifically timed or duplicate network packets, an attacker could cause the system to repeatedly re-run security setup processes, potentially leading to a denial-of-service condition.
Technical details
A race condition and state management flaw exists in net/rxrpc/conn_event.c within the Linux kernel. The rxrpc_process_event function fails to properly lock and verify the connection state before processing RXRPC_PACKET_TYPE_RESPONSE packets. Specifically, duplicate or late RESPONSE packets could trigger the security initialization and response verification paths even after a connection had transitioned out of the RXRPC_CONN_SERVICE_CHALLENGING state. An attacker can exploit this by sending unsolicited or redundant RESPONSE packets over the network to trigger unnecessary re-processing. The fix introduces proper state_lock checks and a local flag to ensure security setup only occurs once during the valid state transition.
Affected products
- Linux Linux Kernel 2.6.22 to 6.6.136, 6.7 to 6.12.84, 6.13 to 6.18.23, 6.19 to 6.19.13, 7.0-rc1 to 7.0-rc7
Timeline
- 2026-04-25: disclosed
- 2026-04-25: advisory
- 2026-04-18: patched: Mainline patch committed by Greg Kroah-Hartman
References
- https://git.kernel.org/stable/c/03fd2ef73cb4ffd0af100a95b634af54f474414e
- https://git.kernel.org/stable/c/0afdfd4941c1b60a1f5c361760daa970edca60cd
- https://git.kernel.org/stable/c/29b44d904dceb832be880def08b8cb17a0aba91c
- https://git.kernel.org/stable/c/6c3a0fbdafef8316e34ae22333e317a341e737cd
- https://git.kernel.org/stable/c/a1a8efde03a40b6c658d580e96644d9b9a2a0d3a
- https://git.kernel.org/stable/c/a6bcf8010af093fe04f7100562e9542ab7882585
- https://git.kernel.org/stable/c/c43ffdcfdbb5567b1f143556df8a04b4eeea041c