Executive brief
A vulnerability in the Linux kernel's networking component could allow for data corruption. Specifically, when the system handles certain encrypted network packets, it may inadvertently corrupt the page cache, which is the system's primary method for storing frequently accessed data from disk. This could lead to system instability or the corruption of local files and application data.
Technical details
A vulnerability exists in the Linux kernel rxrpc implementation where in-place decryption of DATA packets can lead to page cache corruption. This occurs when packets transmitted locally via splice() are decrypted directly within the shared packet buffer (sk_buff). An attacker with local access could potentially exploit this to corrupt kernel memory or file system caches. The fix involves introducing a dedicated bounce buffer for decryption in the recvmsg() path, ensuring the original sk_buff remains unmodified and the data is correctly aligned for cryptographic algorithms. This issue is an improvement over the previous fix for CVE-2026-43500.
Affected products
- Linux Linux Kernel d0d5c0cd1e71 to a05bf6d9e621
Timeline
- 2026-05-29: patched: Initial patch authored by David Howells
- 2026-07-19: disclosed: CVE published to NVD dataset
References
- https://git.kernel.org/stable/c/46cb765e2e5ad52303ea157e10d370bb6b7acbbf
- https://git.kernel.org/stable/c/a05bf6d9e621fa71e89ccebe3047ba45218d7b38
- https://git.kernel.org/stable/c/b94a6ccbaf1104dd980150a65fdeb2f69d17d2f5
- https://git.kernel.org/stable/c/c580087743712112778a06d65a4074053072d7bf
- https://git.kernel.org/stable/c/d2bc90cf6c75cb96d2ce549be6c35efa3099d25b