In the Linux kernel, the following vulnerability has been resolved:
rxrpc: only handle RESPONSE during service challenge
Only process RESPONSE packets while the service connection is still in
RXRPC_CONN_SERVICE_CHALLENGING. Check that state under state_lock before
running response verification and security initialization, then use a local
secured flag to decide whether to queue the secured-connection work after
the state transition. This keeps duplicate or late RESPONSE packets from
re-running the setup path and removes the unlocked post-transition state
test.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-04-25 09:16
Updated : 2026-06-17 10:34
NVD link : CVE-2026-31676
Mitre link : CVE-2026-31676
CVE.ORG link : CVE-2026-31676
JSON object : View
Products Affected
linux
- linux_kernel
CWE
