CVE-2026-74435: Linux

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc rxrpc_recvmsg_data() calls rxrpc_verify_data() whenever the rxrpc_call.rx_dec_buffer is unallocated and assumes that upon successful return that rx_dec_buffer must be allocated. However, rxrpc_verify_data() does not request an allocation if the rxrpc_skb_priv.len is zero. In addition, failure to allocate rx_dec_buffer will result in a call to skb_copy_bits() with a NULL destination which can trigger a NULL pointer dereference. To prevent these issues rxrpc_verify_data() is modified to always attempt to allocate the rxrpc_call.rx_dec_buffer if it is NULL. This issue was identified with assistance of a private sashiko instance.

Affected products

  • Linux Linux: from 6.6.143, before 6.6.145 (fixed in 6.6.145); from 6.12.93, before 6.12.97 (fixed in 6.12.97); from 6.18.35, before 6.18.40 (fixed in 6.18.40); from 7.0.11, before 7.1 (fixed in 7.1); from 7.1, before 7.1.5 (fixed in 7.1.5)

Published 2026-08-15. Last modified 2026-08-17.