Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-31631

Опубликовано: 24 апр. 2026
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread in rxgk_do_verify_authenticator() Fix rxgk_do_verify_authenticator() to check the buffer size before checking the nonce.

A flaw was found in the Linux kernel, specifically within its rxrpc communication protocol. This vulnerability is a buffer overread, meaning the system attempts to read data beyond the allocated memory buffer in the rxgk_do_verify_authenticator() function. This could potentially allow an attacker to access sensitive information or cause the system to become unavailable.

Отчет

RxGK authenticator parsing could read past skb bounds; upstream tightens length checks. Red Hat treats this as kernel network stack hardening for AFS/RX security paths.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelFix deferred
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelFix deferred
Red Hat Enterprise Linux 7kernel-rtFix deferred
Red Hat Enterprise Linux 8kernelFix deferred
Red Hat Enterprise Linux 8kernel-rtFix deferred
Red Hat Enterprise Linux 9kernelFix deferred
Red Hat Enterprise Linux 9kernel-rtFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-805
https://bugzilla.redhat.com/show_bug.cgi?id=2461573kernel: rxrpc: Fix buffer overread in rxgk_do_verify_authenticator()

EPSS

Процентиль: 31%
0.00385
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread in rxgk_do_verify_authenticator() Fix rxgk_do_verify_authenticator() to check the buffer size before checking the nonce.

CVSS3: 8.2
nvd
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread in rxgk_do_verify_authenticator() Fix rxgk_do_verify_authenticator() to check the buffer size before checking the nonce.

CVSS3: 8.2
debian
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: r ...

CVSS3: 8.2
github
4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread in rxgk_do_verify_authenticator() Fix rxgk_do_verify_authenticator() to check the buffer size before checking the nonce.

EPSS

Процентиль: 31%
0.00385
Низкий

6.3 Medium

CVSS3