CVE-2026-64208 PUBLISHED

crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks

Assigner: Linux
Reserved: 19.07.2026 Published: 24.07.2026 Updated: 24.07.2026

In the Linux kernel, the following vulnerability has been resolved:

crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks

Change the krb5 crypto library to provide facilities to precheck the length of the message about to be decrypted or verified.

Fix AF_RXRPC to make use of this to validate DATA packets secured with RxGK.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a to 585f9f6aef5c4542ac9d6ec45cd7dbc7df9af3ff (excl.)
  • affected from 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a to 9217017f4bce53dddb8d547837f1f707045d64ad (excl.)
  • affected from 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a to 2b50aceafe6606ea52ed42aadd1b4d44a188aade (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.16 is affected
  • unaffected from 0 to 6.16 (excl.)
  • unaffected from 6.18.34 to 6.18.* (incl.)
  • unaffected from 7.0.11 to 7.0.* (incl.)
  • unaffected from 7.1 to * (incl.)

References