PT-2026-36326 · Linux+2 · Linux Kernel+2

CVE-2026-31696

·

Published

2026-04-22

·

Updated

2026-08-25

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description In the rxrpc preparse() function, the non-XDR path for parsing key payloads (used for payloads 28 bytes or smaller) fails to validate the ticket length against AFSTOKEN RK TIX MAX. This differs from the XDR path, which performs this validation correctly. An unprivileged user can provide an excessively large ticket length, which causes the total token size calculation in the rxrpc read() function to exceed AFSTOKEN LENGTH MAX, resulting in a system warning.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-85433
BDU:2026-08757
CVE-2026-31696
ECHO-93EE-8082-FBDD
OPENSUSE-SU-2026:10793-1
USN-8488-1
USN-8488-2
USN-8507-1
USN-8567-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8597-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8610-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4
USN-8665-1
USN-8668-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu