HIGHCVE-2026-46010Published Modified CNA Linux
CVE-2026-46010: rxrpc: Fix error handling in rxgk_extract_token()
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix error handling in rxgk_extract_token() Fix a missing bit of error handling in rxgk_extract_token(): in the event that rxgk_decrypt_skb() returns -ENOMEM, it should just return that rather than continuing on (for anything else, it generates an abort).
Metrics
- CVSS v3.1
- 8.1
- Severity
- HIGH
- Fixed in
- 0
- Affected Products
- 2
Fix available
0293095ef618818852bac5488c1bc223935e2ca173476c8bb960f48e49355d6f93fb7673211e0163f6.176.18.277.0.47.1-rc1c52803e925604e2a17962ab0c99dce2d3f7238db
Affected packages
- Linux / Linux< 293095ef618818852bac5488c1bc223935e2ca17 (from 64863f4ca4945bdb62ce2b30823f39ea9fe95415) · < c52803e925604e2a17962ab0c99dce2d3f7238db (from 64863f4ca4945bdb62ce2b30823f39ea9fe95415) · < 3476c8bb960f48e49355d6f93fb7673211e0163f (from 64863f4ca4945bdb62ce2b30823f39ea9fe95415) · 8ac99c57029e13ebb5fb0d634925abedef32b53a · < 6.17 (from 6.16.9)
- Linux / Linux6.17Fixed in 0, 6.18.27, 7.0.4, 7.1-rc1
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H