CVE-2026-45988 PUBLISHED

rxrpc: Fix re-decryption of RESPONSE packets

Assigner: Linux
Reserved: 13.05.2026 Published: 27.05.2026 Updated: 27.05.2026

In the Linux kernel, the following vulnerability has been resolved:

rxrpc: Fix re-decryption of RESPONSE packets

If a RESPONSE packet gets a temporary failure during processing, it may end up in a partially decrypted state - and then get requeued for a retry.

Fix this by just discarding the packet; we will send another CHALLENGE packet and thereby elicit a further response. Similarly, discard an incoming CHALLENGE packet if we get an error whilst generating a RESPONSE; the server will send another CHALLENGE.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 17926a79320afa9b95df6b977b40cca6d8713cea to d61482be4aae1835b78875761206241835a7510e (excl.)
  • affected from 17926a79320afa9b95df6b977b40cca6d8713cea to 7b89868305052b94a91b708c462bc2281fa42a4a (excl.)
  • affected from 17926a79320afa9b95df6b977b40cca6d8713cea to 76cb9a2d252274adfae6e293a292434631a7d472 (excl.)
  • affected from 17926a79320afa9b95df6b977b40cca6d8713cea to f55b383070170e988e4dec28be2af1714d258521 (excl.)
  • affected from 17926a79320afa9b95df6b977b40cca6d8713cea to 0422e7a4883f25101903f3e8105c0808aa5f4ce9 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 2.6.22 is affected
  • unaffected from 0 to 2.6.22 (excl.)
  • unaffected from 6.6.140 to 6.6.* (incl.)
  • unaffected from 6.12.86 to 6.12.* (incl.)
  • unaffected from 6.18.27 to 6.18.* (incl.)
  • unaffected from 7.0.4 to 7.0.* (incl.)
  • unaffected from 7.1-rc1 to * (incl.)

References