CVE-2026-64208 is a vulnerability in Linux Kernel
Published on July 24, 2026
crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks
In the Linux kernel, the following vulnerability has been resolved:
crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks
Change the krb5 crypto library to provide facilities to precheck the length
of the message about to be decrypted or verified.
Fix AF_RXRPC to make use of this to validate DATA packets secured with
RxGK.
Products Associated with CVE-2026-64208
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a and below 585f9f6aef5c4542ac9d6ec45cd7dbc7df9af3ff is affected.
- Version 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a and below 9217017f4bce53dddb8d547837f1f707045d64ad is affected.
- Version 9d1d2b59341f58126a69b51f9f5f8ccb9f12e54a and below 2b50aceafe6606ea52ed42aadd1b4d44a188aade is affected.
- Version 6.16 is affected.
- Before 6.16 is unaffected.
- Version 6.18.34, <= 6.18.* is unaffected.
- Version 7.0.11, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.