CVE-2026-31638 (GCVE-0-2026-31638)
Vulnerability from cvelistv5
Published
2026-04-24 14:44
Modified
2026-08-05 12:24
Summary
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Only put the call ref if one was acquired rxrpc_input_packet_on_conn() can process a to-client packet after the current client call on the channel has already been torn down. In that case chan->call is NULL, rxrpc_try_get_call() returns NULL and there is no reference to drop. The client-side implicit-end error path does not account for that and unconditionally calls rxrpc_put_call(). This turns a protocol error path into a kernel crash instead of rejecting the packet. Only drop the call reference if one was actually acquired. Keep the existing protocol error handling unchanged.
Impacted products
Vendor Product Version
Linux Linux Version: 5e6ef4f1017c7f844e305283bbd8875af475e2fc
Version: 5e6ef4f1017c7f844e305283bbd8875af475e2fc
Version: 5e6ef4f1017c7f844e305283bbd8875af475e2fc
Version: 5e6ef4f1017c7f844e305283bbd8875af475e2fc
Version: 5e6ef4f1017c7f844e305283bbd8875af475e2fc
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/rxrpc/io_thread.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "b8f66447448d6c305a51413a67ec8ed26aa7d1dd",
              "status": "affected",
              "version": "5e6ef4f1017c7f844e305283bbd8875af475e2fc",
              "versionType": "git"
            },
            {
              "lessThan": "0c156aff8a2d4fa0d61db7837641975cf0e5452d",
              "status": "affected",
              "version": "5e6ef4f1017c7f844e305283bbd8875af475e2fc",
              "versionType": "git"
            },
            {
              "lessThan": "8299ca146489664e3c0c90a3b8900d8335b1ede4",
              "status": "affected",
              "version": "5e6ef4f1017c7f844e305283bbd8875af475e2fc",
              "versionType": "git"
            },
            {
              "lessThan": "9fb09861e2b8d1abfe2efaf260c9f1d30080ea38",
              "status": "affected",
              "version": "5e6ef4f1017c7f844e305283bbd8875af475e2fc",
              "versionType": "git"
            },
            {
              "lessThan": "6331f1b24a3e85465f6454e003a3e6c22005a5c5",
              "status": "affected",
              "version": "5e6ef4f1017c7f844e305283bbd8875af475e2fc",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/rxrpc/io_thread.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.2"
            },
            {
              "lessThan": "6.2",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.135",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.82",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.23",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.19.*",
              "status": "unaffected",
              "version": "6.19.13",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.135",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.82",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.23",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.19.13",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Only put the call ref if one was acquired\n\nrxrpc_input_packet_on_conn() can process a to-client packet after the\ncurrent client call on the channel has already been torn down.  In that\ncase chan-\u003ecall is NULL, rxrpc_try_get_call() returns NULL and there is\nno reference to drop.\n\nThe client-side implicit-end error path does not account for that and\nunconditionally calls rxrpc_put_call().  This turns a protocol error\npath into a kernel crash instead of rejecting the packet.\n\nOnly drop the call reference if one was actually acquired.  Keep the\nexisting protocol error handling unchanged."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - RXRPC runs over UDP and the vulnerable path is reached by received to-client RXRPC packets processed by the kernel RXRPC I/O thread. A malicious remote RXRPC peer can send the crafted packet after a client call has been torn down.\nAC:L - The attacker-controlled peer can observe the connection/call values during the normal exchange and choose when to send a packet with a higher callNumber after teardown. No hard-to-win race or external condition is required.\nPR:N - The packet receive path does not require the attacker to have local credentials or kernel capabilities. Any remote peer able to send matching RXRPC packets for an extant client connection can reach the vulnerable logic.\nUI:N - Once the victim system has an RXRPC client connection, exploitation is triggered by network packets alone. No interactive victim action is needed at the point of exploitation.\nS:U - The impact is within the same kernel security authority. This is not a VM escape, IOMMU bypass, or cross-scope sandbox boundary violation.\nC:N - The bug is an unconditional rxrpc_put_call(NULL), producing a NULL pointer dereference rather than a controllable read primitive. No information disclosure is apparent from the fault.\nI:N - The defect does not corrupt attacker-controlled memory or provide a write primitive. It is a protocol error path converted into a NULL dereference crash.\nA:H - Dereferencing the NULL call pointer in rxrpc_put_call() can oops or panic the kernel. A remote peer can repeat the trigger against vulnerable clients, causing high availability impact."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:24:03.234Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b8f66447448d6c305a51413a67ec8ed26aa7d1dd"
        },
        {
          "url": "https://git.kernel.org/stable/c/0c156aff8a2d4fa0d61db7837641975cf0e5452d"
        },
        {
          "url": "https://git.kernel.org/stable/c/8299ca146489664e3c0c90a3b8900d8335b1ede4"
        },
        {
          "url": "https://git.kernel.org/stable/c/9fb09861e2b8d1abfe2efaf260c9f1d30080ea38"
        },
        {
          "url": "https://git.kernel.org/stable/c/6331f1b24a3e85465f6454e003a3e6c22005a5c5"
        }
      ],
      "title": "rxrpc: Only put the call ref if one was acquired",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-31638",
    "datePublished": "2026-04-24T14:44:52.122Z",
    "dateReserved": "2026-03-09T15:48:24.125Z",
    "dateUpdated": "2026-08-05T12:24:03.234Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…