Junglewise Threat Intelligence

CVE-2026-46000: Linux Kernel rxrpc information disclosure in RESPONSE packet handling

CVE-2026-46000 · Severity: info · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's RxRPC network protocol implementation could allow sensitive network data to be inadvertently exposed or corrupted. When the system processes certain security response packets, it performs decryption directly on the data buffer; if that buffer is being monitored by a packet sniffer, the sniffer may see modified or 'corrupted' data. This issue primarily impacts the integrity of network monitoring and could potentially lead to information leakage in specific configurations.

Technical details

A flaw was found in the Linux kernel's AF_RXRPC socket implementation. The security operations responsible for verifying RESPONSE packets perform in-place decryption on the sk_buff. If the sk_buff is cloned (e.g., because a packet sniffer like tcpdump is active), the sniffer sees the modified (decrypted) bits, which appears as packet corruption or unintended data exposure. The fix introduces 'rxrpc_verify_response' to check if a buffer is cloned and, if so, creates an unshared copy before decryption. This ensures that in-place modifications do not affect other consumers of the original packet buffer.

Affected products

  • Linux Linux Kernel v6.12.86 and other stable branches

Timeline

  • 2026-04-22: patched: Initial patch authored by David Howells
  • 2026-05-27: disclosed: CVE-2026-46000 published

References

Related threats