CVE-2026-23118

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/02/2026
Last modified:
14/02/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> rxrpc: Fix data-race warning and potential load/store tearing<br /> <br /> Fix the following:<br /> <br /> BUG: KCSAN: data-race in rxrpc_peer_keepalive_worker / rxrpc_send_data_packet<br /> <br /> which is reporting an issue with the reads and writes to -&gt;last_tx_at in:<br /> <br /> conn-&gt;peer-&gt;last_tx_at = ktime_get_seconds();<br /> <br /> and:<br /> <br /> keepalive_at = peer-&gt;last_tx_at + RXRPC_KEEPALIVE_TIME;<br /> <br /> The lockless accesses to these to values aren&amp;#39;t actually a problem as the<br /> read only needs an approximate time of last transmission for the purposes<br /> of deciding whether or not the transmission of a keepalive packet is<br /> warranted yet.<br /> <br /> Also, as -&gt;last_tx_at is a 64-bit value, tearing can occur on a 32-bit<br /> arch.<br /> <br /> Fix both of these by switching to an unsigned int for -&gt;last_tx_at and only<br /> storing the LSW of the time64_t. It can then be reconstructed at need<br /> provided no more than 68 years has elapsed since the last transmission.

Impact