RMPP Response Processing Vulnerability in Linux Kernel
CVE-2026-68425
What is CVE-2026-68425?
A vulnerability exists in the Linux kernel's handling of RMPP (Reliable Message Protocol) responses. This issue arises when the kernel begins reassembly of DATA responses prematurely, without first validating that the response matches an outstanding send request. As a result, unsolicited RMPP responses can allocate or extend receive state in the kernel prior to proper verification of the sender's TID and address. The proposed solution implements a check requiring a complete match before entering the reassembly process, ensuring that unmatched responses are discarded and thus mitigating potential risks associated with receiving and processing arbitrary messages.
Affected Version(s)
Linux fa619a77046bef30478697aba0553991033afb8e
Linux fa619a77046bef30478697aba0553991033afb8e < 6e1bd7f590b0ccfee07f7fe1d48b92059bd37d72
Linux fa619a77046bef30478697aba0553991033afb8e < 98d2d468b4faa1fdc68c0c6c238389906ee3490c