SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64208

HIGH · CVSS 7.5 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

A vulnerability in the Linux kernel's krb5 crypto library and AF_RXRPC allows for the processing of improperly sized messages during decryption or verification, potentially leading to denial-of-service attacks or unauthorized access. Organizations using Linux systems, particularly those relying on Kerberos authentication and RxRPC for secure communications, should prioritize addressing this issue to mitigate risks associated with message integrity and system stability.

CVE
CVE-2026-64208
Severity
HIGH
CVSS
7.5
EPSS
0.43%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks Change the krb5 crypto library to provide facilities to precheck the length of the message about to be decrypted or verified. Fix AF_RXRPC to make use of this to validate DATA packets secured with RxGK.

Related CVEs

Other vulnerabilities affecting the same vendor(s)