High severity7.5NVD Advisory· Published Jul 24, 2026· Updated Aug 12, 2026
CVE-2026-64208
CVE-2026-64208
Description
In the Linux kernel, the following vulnerability has been resolved:
crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks
Change the krb5 crypto library to provide facilities to precheck the length of the message about to be decrypted or verified.
Fix AF_RXRPC to make use of this to validate DATA packets secured with RxGK.
Affected products
7cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.16,<6.18.34
- cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
3News mentions
1- Linux Kernel: 25 Vulnerabilities Across Subsystems Addressed in Coordinated July 2026 DisclosureVypr Intelligence · Jul 25, 2026