CVE-2026-31642

MEDIUM

rxrpc: Fix call removal to use RCU safe deletion

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix call removal to use RCU safe deletion Fix rxrpc call removal from the rxnet->calls list to use list_del_rcu() rather than list_del_init() to prevent stuffing up reading /proc/net/rxrpc/calls from potentially getting into an infinite loop. This, however, means that list_empty() no longer works on an entry that's been deleted from the list, making it harder to detect prior deletion. Fix this by: Firstly, make rxrpc_destroy_all_calls() only dump the first ten calls that are unexpectedly still on the list. Limiting the number of steps means there's no need to call cond_resched() or to remove calls from the list here, thereby eliminating the need for rxrpc_put_call() to check for that. rxrpc_put_call() can then be fixed to unconditionally delete the call from the list as it is the only place that the deletion occurs.

Scores

CVSS v3 5.5
EPSS 0.0012
EPSS Percentile 2.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-835
Status published
Products (28)
linux/Kernel 4.13.0 - 5.10.258linux
linux/Kernel 5.11.0 - 5.15.209linux
linux/Kernel 5.16.0 - 6.1.175linux
linux/Kernel 6.13.0 - 6.18.23linux
linux/Kernel 6.19.0 - 6.19.13linux
linux/Kernel 6.2.0 - 6.6.135linux
linux/Kernel 6.7.0 - 6.12.82linux
Linux/Linux < 4.13
Linux/Linux 2baec2c3f854d1f79c7bb28386484e144e864a14 - 146d4ab94cf129ee06cd467cb5c71368a6b5bad6
Linux/Linux 2baec2c3f854d1f79c7bb28386484e144e864a14 - 280efb85e9759881a9d31d0874baa04583cb6c09
... and 18 more
Published Apr 24, 2026
Tracked Since Apr 24, 2026