Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to cause system instability or potentially gain unauthorized access. The issue occurs when the system processes specific security keys used for network communication. An attacker with basic access to the system could exploit this to crash the kernel or potentially execute malicious code.
Technical details
A vulnerability exists in the rxrpc_preparse() function within the Linux kernel's AF_RXRPC implementation. While the XDR parsing path correctly validates ticket lengths, the non-XDR path (used for payloads <= 28 bytes) fails to check the ticket_length against AFSTOKEN_RK_TIX_MAX. An unprivileged local user can provide a specially crafted key payload with an excessively large ticket length. When this key is subsequently read via rxrpc_read(), it can trigger a WARN_ON() or lead to an out-of-bounds write (CWE-787) because the calculated token size exceeds internal limits. Patches have been released for various stable kernel branches.
Affected products
- Linux Linux Kernel 3.17 to 6.6.136, 6.7 to 6.12.84, 6.13 to 6.18.25, 6.19 to 7.0.2
Timeline
- 2026-04-22: other: Vulnerability reported by Anderson Nascimento
- 2026-05-01: disclosed: Initial CVE publication
- 2026-06-01: patched: Final stable branch patches applied
References
- https://git.kernel.org/stable/c/1fa36cf495b0023e8475d038535c05e4063211e1
- https://git.kernel.org/stable/c/41a117dd80371343babc52198d1114e83eb37627
- https://git.kernel.org/stable/c/4458757c020592a3094366e0fb20457383b42f92
- https://git.kernel.org/stable/c/44714dfda386884919ba366411880b6fb3c3efd3
- https://git.kernel.org/stable/c/9a397aa9b5e53ca63d4d6aefb542832eca389618
- https://git.kernel.org/stable/c/a1be1c9ece26cea69654f28b255ff9a7906b897b
- https://git.kernel.org/stable/c/ac33733b10b484d666f97688561670afd5861383