๐Ÿ” CVE Alert

CVE-2026-89550

CRITICAL 9.8

SUNRPC: svcauth_gss: enforce krb5 token minimum length

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svcauth_gss: enforce krb5 token minimum length svcauth_gss_unwrap_priv() validates only an upper bound on the wire-supplied opaque length before handing the buffer to gss_unwrap(): if (len > xdr_stream_remaining(xdr)) goto unwrap_failed; offset = xdr_stream_pos(xdr); ... maj_stat = gss_unwrap(ctx, offset, offset + len, buf); The wire value `len` flows unchanged as the upper bound into the krb5 unwrap path, so a len in [0, 16] passes this check and is handed to gss_unwrap(). For a krb5 v2 context that lands in gss_krb5_unwrap_v2(), which reads the 16-byte RFC 4121 token header fields at ptr+4 and ptr+6 and then calls rotate_left() before any integrity check. With a sub-header length the header reads run past the token, and _rotate_left()'s `shift %= buf->len` path can divide by zero when buf->len has been driven to zero by the truncated token. A header-only token (len == 16) is equally invalid: with a non-zero RRC field and the opaque blob ending at the XDR buffer boundary, rotate_left() builds a zero-length subbuffer, reaching the same division. Reject the token at the server entry point before it reaches the krb5 unwrap core. A valid sealed RFC 4121 token must contain the 16-byte header plus at least some encrypted payload. Fix by adding a minimum-length check immediately after the existing upper-bound check: if (len <= GSS_KRB5_TOK_HDR_LEN) goto unwrap_failed;

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
7c9fdcfb1b64c47ed618c103b617af3f86e1239c < 0ea5b0c7f212c2772d32c2b88287b89a9cdf6edd 7c9fdcfb1b64c47ed618c103b617af3f86e1239c < dd6afc6cab8c5d387d1ed2f069562ef7bdadd651 7c9fdcfb1b64c47ed618c103b617af3f86e1239c < de942dd8c2c8358bcad04ce44271954c48924423 7c9fdcfb1b64c47ed618c103b617af3f86e1239c < 2eed1e6a976a44015c3ee78841fe336796e2b21c 7c9fdcfb1b64c47ed618c103b617af3f86e1239c < a919c5c88769cf8fb3ec071e6078d830bf512489
Linux / Linux
2.6.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/0ea5b0c7f212c2772d32c2b88287b89a9cdf6edd git.kernel.org: https://git.kernel.org/stable/c/dd6afc6cab8c5d387d1ed2f069562ef7bdadd651 git.kernel.org: https://git.kernel.org/stable/c/de942dd8c2c8358bcad04ce44271954c48924423 git.kernel.org: https://git.kernel.org/stable/c/2eed1e6a976a44015c3ee78841fe336796e2b21c git.kernel.org: https://git.kernel.org/stable/c/a919c5c88769cf8fb3ec071e6078d830bf512489