CyberRota
Live Feed
Back to database

CVE-2026-31676

HIGH · CVSS 7.5 EPSS 0.06%

Source: NVD + CISA KEV + EPSS · Published: 2026-04-25 · Last synced: 2026-05-25

CyberRota Analysis

Detaylı analiz gerekiyor.

CVE
CVE-2026-31676
Severity
HIGH
CVSS
7.5
EPSS
0.06%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: rxrpc: only handle RESPONSE during service challenge Only process RESPONSE packets while the service connection is still in RXRPC_CONN_SERVICE_CHALLENGING. Check that state under state_lock before running response verification and security initialization, then use a local secured flag to decide whether to queue the secured-connection work after the state transition. This keeps duplicate or late RESPONSE packets from re-running the setup path and removes the unlocked post-transition state test.