๐Ÿ” CVE Alert

CVE-2026-89541

CRITICAL 9.8

SUNRPC: harden gss_unwrap_resp_priv length checks

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_unwrap_resp_priv length checks gss_unwrap_resp_priv() validates the RPCSEC_GSS opaque length with offset = (u8 *)(p) - (u8 *)head->iov_base; if (offset + opaque_len > rcv_buf->len) goto unwrap_failed; maj_stat = gss_unwrap(ctx->gc_gss_ctx, offset, offset + opaque_len, rcv_buf); Both operands are u32 and the sum is computed in u32. A reply with opaque_len near 0xffffffff makes offset + opaque_len wrap to a small value that is below rcv_buf->len, so the bound check passes and gss_unwrap() is called with end < begin. The check also lacks a lower bound, so any opaque_len in [0, GSS_KRB5_TOK_HDR_LEN) is accepted and forwarded to gss_krb5_unwrap_v2(), whose pre-decrypt header reads at ptr+4 and ptr+6 then run past the token. A krb5p NFS server returning a crafted RPCSEC_GSS reply can drive the client into out-of-bounds reads in gss_krb5_unwrap_v2() and the rotate_left() loop that follows. Fix by replacing the single combined check with three guards that are safe in u32 arithmetic and that enforce the RFC 4121 minimum outer token length: if (offset > rcv_buf->len) goto unwrap_failed; if (opaque_len > rcv_buf->len - offset) goto unwrap_failed; if (opaque_len < GSS_KRB5_TOK_HDR_LEN) goto unwrap_failed; The first guard makes the subtraction in the second guard unconditionally safe; offset is derived from a successful xdr_inline_decode() in the head kvec, so in practice it already satisfies the bound. The floor mirrors the server-side check added in commit 5b757c2e57a5 ("SUNRPC: svcauth_gss: enforce krb5 token minimum length").

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
2d2da60c63b67174add32f06e8d54c3a0c5cd9cf < 3691c4b3488d8ca046b9941e5be30c626dbbbb50 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf < 85fa6b12e8f439739ac36ef2aad925f37c8b976a 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf < 401f6a5b338d05bb1069ad814d9f77e3c367854f 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf < 81fd7654a8429718adfcb2a7e03496077f547ed0 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf < 89a15a50f84d32d4b99db86f957427fcbe20a99a 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf < ebcbd2523a8524c3d24e111cdbed8e271d910269 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf < d395c30d570ca6168f0297b191709927d1258273 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf < 87831b92112c81db251d46756d65daa4f91af6a2
Linux / Linux
2.6.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/3691c4b3488d8ca046b9941e5be30c626dbbbb50 git.kernel.org: https://git.kernel.org/stable/c/85fa6b12e8f439739ac36ef2aad925f37c8b976a git.kernel.org: https://git.kernel.org/stable/c/401f6a5b338d05bb1069ad814d9f77e3c367854f git.kernel.org: https://git.kernel.org/stable/c/81fd7654a8429718adfcb2a7e03496077f547ed0 git.kernel.org: https://git.kernel.org/stable/c/89a15a50f84d32d4b99db86f957427fcbe20a99a git.kernel.org: https://git.kernel.org/stable/c/ebcbd2523a8524c3d24e111cdbed8e271d910269 git.kernel.org: https://git.kernel.org/stable/c/d395c30d570ca6168f0297b191709927d1258273 git.kernel.org: https://git.kernel.org/stable/c/87831b92112c81db251d46756d65daa4f91af6a2