Impact
A Linux kernel flaw allows a RESPONSE packet to be in a partially decrypted state when a temporary processing failure occurs. The packet is then requeued for a retry. Because the incomplete decryption is not detected, the system could expose sensitive information through re-decryption of that packet. The patch resolves the issue by discarding the malformed packet and issuing a new CHALLENGE to elicit a fresh, properly encrypted response. The weakness is a cryptographic error, potentially falling under CWE‑327.
Affected Systems
The vulnerability affects the Linux kernel in all releases that implement the rxrpc protocol. No specific vendors, products, or version ranges are listed in the CNA data. The CPE string indicates the entire Linux kernel family. Administrators should verify whether their system kernel includes this bug and plan to update accordingly.
Risk and Exploitability
No CVSS score or EPSS value is available, and the vulnerability is not listed in the CISA KEV catalog. Because the exploitability details are missing from the advisory, the actual severity cannot be quantified from the supplied data. The existing documentation does not describe a known exploitation technique or provide evidence that this flaw has been exploited in the wild. The risk remains theoretical until the kernel is updated to a corrected release.
OpenCVE Enrichment