CyberRota Analysis
AI-GeneratedA vulnerability in the Linux kernel's krb5 crypto library and AF_RXRPC allows for the processing of improperly sized messages during decryption or verification, potentially leading to denial-of-service attacks or unauthorized access. Organizations using Linux systems, particularly those relying on Kerberos authentication and RxRPC for secure communications, should prioritize addressing this issue to mitigate risks associated with message integrity and system stability.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks Change the krb5 crypto library to provide facilities to precheck the length of the message about to be decrypted or verified. Fix AF_RXRPC to make use of this to validate DATA packets secured with RxGK.
Related CVEs
Other vulnerabilities affecting the same vendor(s)