๐Ÿ” CVE Alert

CVE-2026-89542

CRITICAL 9.8

SUNRPC: harden gss_krb5_unwrap_v2 against short tokens

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_krb5_unwrap_v2 against short tokens gss_krb5_unwrap_v2() reads the EC and RRC header fields at ptr+4 and ptr+6 before validating that the token is at least GSS_KRB5_TOK_HDR_LEN (16) bytes long, and its rotate_left() helper passes buf->len - base to xdr_buf_subsegment() without verifying that base <= buf->len. When a caller hands in a sub-16-byte token, or a token whose declared len leaves base past the end of the buffer, three distinct failures follow: gss_krb5_unwrap_v2(offset, len, buf) ptr = buf->head[0].iov_base + offset ec = *(ptr + 4) /* OOB read on short head */ rrc = *(ptr + 6) /* OOB read on short head */ rotate_left(offset + 16, buf, rrc) xdr_buf_subsegment(buf, &subbuf, base, buf->len - base) /* u32 wrap when base > len */ _rotate_left(&subbuf, shift) shift %= buf->len /* divide-by-zero when base == len */ After decryption, the cleanup arithmetic has the same shape: movelen = min_t(unsigned int, buf->head[0].iov_len, len); movelen -= offset + GSS_KRB5_TOK_HDR_LEN + headskip; BUG_ON(offset + GSS_KRB5_TOK_HDR_LEN + headskip + movelen > buf->head[0].iov_len); The BUG_ON re-adds the value just subtracted, so it reduces to min(A, B) > A and is permanently false; it cannot catch the unsigned underflow of movelen, which then drives a ~UINT_MAX-byte memmove(). Add four defense-in-depth guards inside the unwrap core so it is safe regardless of what its callers validate: - reject tokens with len - offset < GSS_KRB5_TOK_HDR_LEN before touching ptr+4/ptr+6; - bail from rotate_left() when buf->len <= base, covering both the underflow and zero-length cases; - return early from _rotate_left() when buf->len is zero, so the shift %= buf->len modulo cannot fault; - replace the dead BUG_ON with a live check that returns GSS_S_DEFECTIVE_TOKEN before the movelen subtraction.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
de9c17eb4a912c9028f7b470eb80815144883b26 < 299d281c7225ded15b28cb861a98d818d82787fc de9c17eb4a912c9028f7b470eb80815144883b26 < 84ddbc8d084c0251d534f14f5d1a7da05be56404 de9c17eb4a912c9028f7b470eb80815144883b26 < 075d7cfc4df8c54cb202ba8b28420370c03ba9b6 de9c17eb4a912c9028f7b470eb80815144883b26 < f2591660e0eb263c9415bf0d0bb1b111e62df7a4 de9c17eb4a912c9028f7b470eb80815144883b26 < dddcb0f4b7e27fac16a78ea9a1c8ec2e8a241087 de9c17eb4a912c9028f7b470eb80815144883b26 < 806584a4b67a7233870c33e5b8f872e76dd02988 de9c17eb4a912c9028f7b470eb80815144883b26 < a7894e10572d53eb10109b8d07459cc8d3435811 de9c17eb4a912c9028f7b470eb80815144883b26 < 6959297aaa9572783d620a226d73c3fb94494888
Linux / Linux
2.6.35

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/299d281c7225ded15b28cb861a98d818d82787fc git.kernel.org: https://git.kernel.org/stable/c/84ddbc8d084c0251d534f14f5d1a7da05be56404 git.kernel.org: https://git.kernel.org/stable/c/075d7cfc4df8c54cb202ba8b28420370c03ba9b6 git.kernel.org: https://git.kernel.org/stable/c/f2591660e0eb263c9415bf0d0bb1b111e62df7a4 git.kernel.org: https://git.kernel.org/stable/c/dddcb0f4b7e27fac16a78ea9a1c8ec2e8a241087 git.kernel.org: https://git.kernel.org/stable/c/806584a4b67a7233870c33e5b8f872e76dd02988 git.kernel.org: https://git.kernel.org/stable/c/a7894e10572d53eb10109b8d07459cc8d3435811 git.kernel.org: https://git.kernel.org/stable/c/6959297aaa9572783d620a226d73c3fb94494888