RMPP Response Processing Vulnerability in Linux Kernel
CVE-2026-68425

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-68425?

A vulnerability exists in the Linux kernel's handling of RMPP (Reliable Message Protocol) responses. This issue arises when the kernel begins reassembly of DATA responses prematurely, without first validating that the response matches an outstanding send request. As a result, unsolicited RMPP responses can allocate or extend receive state in the kernel prior to proper verification of the sender's TID and address. The proposed solution implements a check requiring a complete match before entering the reassembly process, ensuring that unmatched responses are discarded and thus mitigating potential risks associated with receiving and processing arbitrary messages.

Affected Version(s)

Linux fa619a77046bef30478697aba0553991033afb8e

Linux fa619a77046bef30478697aba0553991033afb8e < 6e1bd7f590b0ccfee07f7fe1d48b92059bd37d72

Linux fa619a77046bef30478697aba0553991033afb8e < 98d2d468b4faa1fdc68c0c6c238389906ee3490c

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.