ACK: [SRU][Q][PATCH 0/1] CVE-2026-31633
Hui Wang
hui.wang at canonical.com
Tue Jun 23 09:19:59 UTC 2026
Acked-by: Hui Wang <hui.wang at canonical.com>
On 6/23/26 10:21, Cengiz Can via kernel-team wrote:
> https://ubuntu.com/security/CVE-2026-31633
>
> [ Impact ]
>
> In rxgk_verify_response() in the rxrpc networking code, there is a potential
> integer overflow caused by rounding up token_len before validating it against
> the packet length. This allows the length check to be bypassed, leading to
> memory corruption that an attacker could exploit over the network. Given the
> rxrpc/AF_RXRPC GSSAPI security class is reachable from incoming network
> traffic, this is a high-severity vulnerability with a CVSS score of 9.8.
>
> [ Fix ]
>
> questing: clean cherry-pick
>
> [ Test Plan ]
>
> Boot tested.
>
> [ Where Problems Could Occur ]
>
> A regression in this fix could affect the rxrpc subsystem's yfs-rxgk security
> class, potentially causing valid GSSAPI responses to be rejected or otherwise
> disrupting AFS/rxrpc connections that rely on rxgk authentication.
>
More information about the kernel-team
mailing list