CVE-2026-31631 PUBLISHED

rxrpc: Fix buffer overread in rxgk_do_verify_authenticator()

Assigner: Linux
Reserved: 09.03.2026 Published: 24.04.2026 Updated: 24.04.2026

In the Linux kernel, the following vulnerability has been resolved:

rxrpc: Fix buffer overread in rxgk_do_verify_authenticator()

Fix rxgk_do_verify_authenticator() to check the buffer size before checking the nonce.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a to 794586789800b16dcbe235452494f4223ac80413 (excl.)
  • affected from 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a to 1c4422d8be81718ecb15d79aedff607323085201 (excl.)
  • affected from 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a to f564af387c8c28238f8ebc13314c589d7ba8475d (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.16 is affected
  • unaffected from 0 to 6.16 (excl.)
  • unaffected from 6.18.23 to 6.18.* (incl.)
  • unaffected from 6.19.13 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References