rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc
Summary
| CVE | CVE-2026-74435 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 06:22:45 UTC |
| Updated | 2026-08-15 06:22:45 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc
rxrpc_recvmsg_data() calls rxrpc_verify_data() whenever the
rxrpc_call.rx_dec_buffer is unallocated and assumes that upon
successful return that rx_dec_buffer must be allocated.
However, rxrpc_verify_data() does not request an allocation if
the rxrpc_skb_priv.len is zero.
In addition, failure to allocate rx_dec_buffer will result in a
call to skb_copy_bits() with a NULL destination which can
trigger a NULL pointer dereference.
To prevent these issues rxrpc_verify_data() is modified to
always attempt to allocate the rxrpc_call.rx_dec_buffer if it
is NULL.
This issue was identified with assistance of a private
sashiko instance. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected a05bf6d9e621fa71e89ccebe3047ba45218d7b38 8bbede0afced346b24e4fbde0c68cf12980ba948 git |
Not specified |
| CNA |
Linux |
Linux |
affected b94a6ccbaf1104dd980150a65fdeb2f69d17d2f5 6563b4eb38c35d75892445bcf8aacdc29914821c git |
Not specified |
| CNA |
Linux |
Linux |
affected 46cb765e2e5ad52303ea157e10d370bb6b7acbbf d3b642cf95d48234590cc91450d8705a9bf6b540 git |
Not specified |
| CNA |
Linux |
Linux |
affected d2bc90cf6c75cb96d2ce549be6c35efa3099d25b a962bc8508592c4d51092edac68579bd8b18fe44 git |
Not specified |
| CNA |
Linux |
Linux |
affected d2bc90cf6c75cb96d2ce549be6c35efa3099d25b 16c8ae9735c5bd7e54dd7478d6348e0fc860842d git |
Not specified |
| CNA |
Linux |
Linux |
affected c580087743712112778a06d65a4074053072d7bf git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.6.143 6.6.145 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.12.93 6.12.97 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 6.18.35 6.18.40 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 7.0.11 7.1 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 7.1 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.145 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.97 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.40 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.5 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/d3b642cf95d48234590cc91450d8705a9bf6b540 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/a962bc8508592c4d51092edac68579bd8b18fe44 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/16c8ae9735c5bd7e54dd7478d6348e0fc860842d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/6563b4eb38c35d75892445bcf8aacdc29914821c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/8bbede0afced346b24e4fbde0c68cf12980ba948 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.