Bug 2482123 (CVE-2026-45988) - CVE-2026-45988 kernel: rxrpc: Fix re-decryption of RESPONSE packets
Summary: CVE-2026-45988 kernel: rxrpc: Fix re-decryption of RESPONSE packets
Keywords:
Status: NEW
Alias: CVE-2026-45988
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-27 15:12 UTC by OSIDB Bzimport
Modified: 2026-05-27 21:58 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-27 15:12:25 UTC
In the Linux kernel, the following vulnerability has been resolved:

rxrpc: Fix re-decryption of RESPONSE packets

If a RESPONSE packet gets a temporary failure during processing, it may end
up in a partially decrypted state - and then get requeued for a retry.

Fix this by just discarding the packet; we will send another CHALLENGE
packet and thereby elicit a further response.  Similarly, discard an
incoming CHALLENGE packet if we get an error whilst generating a RESPONSE;
the server will send another CHALLENGE.


Note You need to log in before you can comment on or make changes to this bug.