CVE-2026-46085

Updated on 27 May 2026

Severity

7.5 High severity

Details

CVSS score
7.5

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix rxkad crypto unalignment handling Fix handling of a packet with a misaligned crypto length. Also handle non-ENOMEM errors from decryption by aborting. Further, remove the WARN_ON_ONCE() so that it can’t be remotely triggered (a trace line can still be emitted). A flaw was found in the Linux kernel’s rxrpc subsystem, specifically in the rxkad crypto unalignment handling. A remote attacker could send a specially crafted packet with a misaligned crypto length. This improper handling could lead to system instability or a denial of service (DoS) due to incorrect decryption error handling and the removal of a remotely triggerable warning mechanism.

Details

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Debian 13 Released
1 kernel
  • 6.12.85-1