CVE-2026-64208
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/07/2026
Last modified:
30/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks<br />
<br />
Change the krb5 crypto library to provide facilities to precheck the length<br />
of the message about to be decrypted or verified.<br />
<br />
Fix AF_RXRPC to make use of this to validate DATA packets secured with<br />
RxGK.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



