CVE-2026-31633: rxrpc: Fix integer overflow in rxgk_verify_response()

Published Apr 24, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

rxrpc: Fix integer overflow in rxgkverifyresponse()

In rxgkverifyresponse(), there's a potential integer overflow due to rounding up tokenlen before checking it, thereby allowing the length check to be bypassed.

Fix this by checking the unrounded value against len too (len is limited as the response must fit in a single UDP packet).

Affected Software

11 affected components
Linux Linux kernel
Linux Linux kernel>=6.16.1<6.18.23
Linux Linux kernel>=6.19<6.19.13
Linux Linux kernel=6.16
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Linux Linux kernel=7.0-rc7

Event History

Apr 24, 2026
CVE Published
via MITRE·02:44 PM
Data Sourced
via MITRE·02:44 PM
DescriptionSeverity
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-31633?

CVE-2026-31633 has been classified as a medium severity vulnerability due to the potential for integer overflow.

2

How do I fix CVE-2026-31633?

To fix CVE-2026-31633, update to the latest version of the Linux kernel that includes the patch addressing this vulnerabilities.

3

What is affected by CVE-2026-31633?

CVE-2026-31633 affects the RXRPC implementation in the Linux kernel.

4

What causes CVE-2026-31633?

CVE-2026-31633 is caused by an integer overflow in the rxgk_verify_response() function due to improper handling of token length.

5

Is CVE-2026-31633 exploitable remotely?

CVE-2026-31633 may be exploitable remotely depending on the configuration and use of RXRPC in the affected Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203