Security Flaw in Linux Kernel's Crypto Library and AF_RXRPC Components
CVE-2026-64208

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-64208?

A vulnerability exists in the Linux kernel's crypto library and AF_RXRPC components, involving a lack of pre-decrypt and pre-verify length checks. This issue allows for potential exploitation during the decryption or verification of messages, as it does not adequately validate the length of incoming messages. The krb5 crypto library has been updated to include facilities for prechecking message lengths, thus improving the security of DATA packets secured with RxGK. This fix addresses the validation process, enhancing protection against malicious packet manipulation.

Affected Version(s)

Linux 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a < 585f9f6aef5c4542ac9d6ec45cd7dbc7df9af3ff

Linux 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a < 9217017f4bce53dddb8d547837f1f707045d64ad

Linux 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a < 2b50aceafe6606ea52ed42aadd1b4d44a188aade

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.