Improper Initialization in Linux kernel - CVE-2026-45988

 

Improper Initialization in Linux kernel - CVE-2026-45988

Published: May 28, 2026


Vulnerability identifier: #VU132497
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-45988
CWE-ID: CWE-665
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper state management in RxRPC packet processing when handling RESPONSE or CHALLENGE packets after a temporary processing failure. A remote attacker can send a sequence of crafted packets that trigger packet reprocessing to cause a denial of service.

The issue can occur when a packet is left in a partially decrypted state and then requeued for retry.


Affected software

Linux kernel
Ubuntu
linux (Ubuntu package)
linux-aws (Ubuntu package)
linux-ibm (Ubuntu package)
linux-raspi (Ubuntu package)
linux-xilinx-zynqmp (Ubuntu package)
linux-gcp-5.15 (Ubuntu package)
linux-oracle-5.15 (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-nvidia-tegra (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-raspi-realtime (Ubuntu package)
linux-hwe-6.17 (Ubuntu package)
linux-azure-fde-6.17 (Ubuntu package)
linux-azure-6.17 (Ubuntu package)
linux-nvidia-6.17 (Ubuntu package)
linux-oem-6.17 (Ubuntu package)
linux-nvidia (Ubuntu package)

How to mitigate CVE-2026-45988

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Ubuntu package) - addressed in versions 3.13.0.214.224, 3.13.0-214.265, 4.15.0.253.237, 4.15.0-253.265, 4.15.0.1149.146, 4.15.0-1149.161, 4.15.0.1156.161, 4.15.0-1156.167, 4.15.0.1176.167, 4.15.0-1176.181, 4.15.0.1187.200~16.04.1, 4.15.0-1187.204, 4.15.0.1204.172, 4.15.0-1204.219, 4.15.0.2095.93, 4.15.0-2095.101, 4.15.0.2112.108, 4.15.0-2112.118, 5.4.0.233.225, 5.4.0-233.253, 5.4.0-233.253~18.04.1, 5.4.0-1065.68, 5.4.0.1079.79, 5.4.0-1079.83, 5.4.0.1120.116, 5.4.0-1120.127, 5.4.0.1135.132, 5.4.0-1135.145, 5.4.0.1159.153, 5.4.0-1159.169+fips1, 5.4.0-1159.169~18.04.1, 5.4.0.1161.108, 5.4.0.1161.159, 5.4.0-1161.172, 5.4.0-1161.172+fips1, 5.4.0-1161.172~18.04.1, 5.4.0.1164.106, 5.4.0.1164.166, 5.4.0-1164.173, 5.4.0-1164.173+fips1, 5.4.0-1164.173~18.04.1, 5.4.0.1166.102, 5.4.0.1166.158, 5.4.0-1166.172, 5.4.0-1166.172+fips1, 5.4.0-1166.172~18.04.1, 5.15.0.183.154, 5.15.0-183.193, 5.15.0-183.193~20.04.1, 5.15.0.185.108, 5.15.0.185.166, 5.15.0-185.195+fips1, 5.15.0-185.195~20.04.1, 5.15.0-1052.52, 5.15.0.1052.54, 5.15.0-1063.63, 5.15.0-1063.63~20.04.1, 5.15.0.1094.93, 5.15.0-1094.102, 5.15.0.1103.99, 5.15.0-1103.105, 5.15.0.1103.107, 5.15.0-1103.108, 5.15.0.1105.102, 5.15.0.1105.109, 5.15.0-1105.109~20.04.1, 5.15.0.1106.105, 5.15.0.1106.106, 5.15.0-1106.107, 5.15.0-1106.112, 5.15.0.1107.106, 5.15.0-1107.113, 5.15.0.1108.104, 5.15.0-1108.114, 5.15.0.1110.114, 5.15.0-1110.119, 5.15.0.1111.101, 5.15.0.1111.107, 5.15.0.1111.108, 5.15.0.1111.114, 5.15.0-1111.118, 5.15.0-1111.118+fips1, 5.15.0-1111.118~20.04.1, 5.15.0-1111.121, 5.15.0-1111.121+fips1, 5.15.0.1116.114, 5.15.0-1116.125, 5.15.0-1116.125~20.04.1, 6.8.0-134.134, 6.8.0-1057.58~22.04.1, 6.8.0-1058.61+fips1, 6.8.0-1058.61~22.04.1, 6.8.0-1060.61, 6.8.0-1060.63+fips1, 6.8.0-1060.63~22.04.1, 6.8.0-1063.69, 6.8.0-1063.69+fips1, 6.8.1-1055.56, 6.8.1-1055.56~22.04.1, 6.17.0-40.40, 7.0.0-27.27
linux-aws (Ubuntu package) - addressed in versions 4.4.0-283.317~14.04.1, 4.4.0.1126.128, 4.4.0-1126.133, 4.4.0.1156.153, 4.4.0-1156.162, 4.15.0.1194.192, 4.15.0-1194.207, 4.15.0.2132.126, 4.15.0-2132.138
linux-ibm (Ubuntu package) - addressed in versions 5.4.0-1107.112, 5.4.0-1107.112~18.04.1, 5.4.0.1107.136
linux-raspi (Ubuntu package) - addressed in versions 5.4.0-1144.157, 5.4.0-1144.157~18.04.1, 5.4.0.1144.175, 5.15.0.1105.103, 5.15.0-1105.108, 6.8.0-1060.64, 6.17.0-1021.21, 7.0.0-1014.14
linux-xilinx-zynqmp (Ubuntu package) - addressed in versions 5.15.0.1074.77, 5.15.0-1074.78
linux-gcp-5.15 (Ubuntu package) - addressed in versions 5.15.0-1106.112~20.04.1, 5.15.0-1111.121~20.04.1
linux-oracle-5.15 (Ubuntu package) - update to 5.15.0-1108.114~20.04.1
linux-azure-fips (Ubuntu package) - addressed in versions 5.15.0.1116.101, 5.15.0-1116.125+fips1, 6.8.0-134.134+fips1, 6.8.0-1062.69+fips1
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1029.30
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1045.48, 6.8.0-1057.58~22.04.1, 6.8.0-1058.61.1, 6.8.0-1058.64, 6.8.0-1060.61~22.04.1, 6.8.0-1060.63~22.04.1, 6.8.0-1063.69~22.04.1
linux-azure-fde (Ubuntu package) - update to 6.8.0-1062.69
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1063.71, 6.8.0-1063.71~22.04.1, 7.0.0-1009.9, 7.0.0-1010.10
linux-raspi-realtime (Ubuntu package) - update to 6.8.0-2049.50
linux-hwe-6.17 (Ubuntu package) - update to 6.17.0-40.40~24.04.1
linux-azure-fde-6.17 (Ubuntu package) - update to 6.17.0-1018.18~24.04.1
linux-azure-6.17 (Ubuntu package) - update to 6.17.0-1021.21~24.04.1
linux-nvidia-6.17 (Ubuntu package) - update to 6.17.0-1026.26
linux-oem-6.17 (Ubuntu package) - update to 6.17.0-1028.28
linux-nvidia (Ubuntu package) - update to 7.0.0-1013.13

External References

Related Security Bulletins