Linux Kernel Untrusted Unsigned Subtraction Vulnerability in RXRPC Component

Vulnerability

A vulnerability has been identified in the Linux kernel's RXRPC component, specifically within the YFS-RXGK security class implementation. The issue arises from an untrusted unsigned subtraction in the ticket length calculation, which could potentially be exploited. This vulnerability affects the Linux kernel stable tree.

Impact

The vulnerability could lead to improper handling of packet data, potentially allowing for response packet decoding errors or inconsistencies in connection management.

Remediation

Users can upgrade to the latest version of the Linux kernel stable tree to address this vulnerability.

Added: Oct 9, 2025, 1:17 PM
Updated: Oct 9, 2025, 4:01 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.3
remediation
7.7
relevance
0.7
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.