CVE-2026-64208: crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks
In the Linux kernel, the following vulnerability has been resolved:
crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks
Change the krb5 crypto library to provide facilities to precheck the length of the message about to be decrypted or verified.
Fix AFRXRPC to make use of this to validate DATA packets secured with RxGK.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Patch RxGK. - Upgrade
Upgrade
crypto/krb5, rxrpcto a version that resolves this vulnerability.Patch Fix lack of pre-decrypt/pre-verify length checks
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64208?
CVE-2026-64208 has a high severity rating of 7.5.
How do I fix CVE-2026-64208?
To fix CVE-2026-64208, ensure you update the Linux kernel to the latest patched version that includes the fix.
What is the impact of CVE-2026-64208?
CVE-2026-64208 may allow attackers to exploit vulnerabilities due to improper length checks before decryption or verification of messages.
Which software is affected by CVE-2026-64208?
CVE-2026-64208 affects the Linux kernel and its associated crypto/krb5 and rxrpc functionalities.
When was CVE-2026-64208 published?
CVE-2026-64208 was published on July 24, 2026.