[SRU][Q][PATCH 0/1] CVE-2026-31633

Cengiz Can cengiz.can at canonical.com
Tue Jun 23 02:21:24 UTC 2026


https://ubuntu.com/security/CVE-2026-31633

[ Impact ]

In rxgk_verify_response() in the rxrpc networking code, there is a potential
integer overflow caused by rounding up token_len before validating it against
the packet length. This allows the length check to be bypassed, leading to
memory corruption that an attacker could exploit over the network. Given the
rxrpc/AF_RXRPC GSSAPI security class is reachable from incoming network
traffic, this is a high-severity vulnerability with a CVSS score of 9.8.

[ Fix ]

questing: clean cherry-pick

[ Test Plan ]

Boot tested.

[ Where Problems Could Occur ]

A regression in this fix could affect the rxrpc subsystem's yfs-rxgk security
class, potentially causing valid GSSAPI responses to be rejected or otherwise
disrupting AFS/rxrpc connections that rely on rxgk authentication.



More information about the kernel-team mailing list