๐Ÿ” CVE Alert

CVE-2026-89551

CRITICAL 9.8

SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow xdr_buf_trim() trims `len` bytes from the tail of an xdr_buf by walking the tail, pages, and head iovecs. Each per-section step uses min_t() so it never removes more bytes than that section holds, but the final accounting at the fix_len label subtracts the total bytes actually consumed from buf->len without any clamp: fix_len: buf->len -= (len - trim); When the caller has set buf->len to a value smaller than the sum of the iov_lens, (len - trim) can exceed buf->len and the unsigned subtraction wraps to near UINT_MAX. gss_krb5_unwrap_v2() reaches xdr_buf_trim() in exactly that state: buf->head[0].iov_len -= GSS_KRB5_TOK_HDR_LEN + headskip; buf->len = len - (GSS_KRB5_TOK_HDR_LEN + headskip); xdr_buf_trim(buf, ec + GSS_KRB5_TOK_HDR_LEN + tailskip); buf->len is a small wire-derived value while the iov_lens are at page scale, so the per-section loops legitimately consume far more bytes than buf->len records. The wrapped buf->len then propagates as the authoritative stream bound into every downstream XDR decoder. Fix by clamping the decrement so buf->len bottoms out at zero: buf->len -= min_t(unsigned int, buf->len, len - trim); On the normal path where the iov_lens sum to buf->len, (len - trim) is always <= buf->len and the result is identical to before. No callers change behavior outside the underflow case.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
4c190e2f913f038c9c91ee63b59cd037260ba353 < a3d77bcd974b8625d16bddf448cb3a1b5e37049c 4c190e2f913f038c9c91ee63b59cd037260ba353 < fa16bbe987b47e771e52eeb1b4540f18d92496ac 4c190e2f913f038c9c91ee63b59cd037260ba353 < a924ac4c78afab71bf82641afa3b62e0c4a8b55e 4c190e2f913f038c9c91ee63b59cd037260ba353 < 4bf59cb0ea5b0ddfbc46a1dc2fa78fc8b9986ce4 4c190e2f913f038c9c91ee63b59cd037260ba353 < e6267cccd7b05cc514e57f2160aa8db85f5c2701 4c190e2f913f038c9c91ee63b59cd037260ba353 < ad0cce80d4af2f74674e8b635d97aa3880e83da8 4c190e2f913f038c9c91ee63b59cd037260ba353 < 85e9602650e9df07190abe817cee3b4d9bc3df17 4c190e2f913f038c9c91ee63b59cd037260ba353 < 3f491306dcb673ff5e78e1044ba450c58978774e
Linux / Linux
3.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/a3d77bcd974b8625d16bddf448cb3a1b5e37049c git.kernel.org: https://git.kernel.org/stable/c/fa16bbe987b47e771e52eeb1b4540f18d92496ac git.kernel.org: https://git.kernel.org/stable/c/a924ac4c78afab71bf82641afa3b62e0c4a8b55e git.kernel.org: https://git.kernel.org/stable/c/4bf59cb0ea5b0ddfbc46a1dc2fa78fc8b9986ce4 git.kernel.org: https://git.kernel.org/stable/c/e6267cccd7b05cc514e57f2160aa8db85f5c2701 git.kernel.org: https://git.kernel.org/stable/c/ad0cce80d4af2f74674e8b635d97aa3880e83da8 git.kernel.org: https://git.kernel.org/stable/c/85e9602650e9df07190abe817cee3b4d9bc3df17 git.kernel.org: https://git.kernel.org/stable/c/3f491306dcb673ff5e78e1044ba450c58978774e