{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89542","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.722Z","datePublished":"2026-09-11T19:44:18.931Z","dateUpdated":"2026-09-14T12:00:49.355Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:00:49.355Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: harden gss_krb5_unwrap_v2 against short tokens\n\ngss_krb5_unwrap_v2() reads the EC and RRC header fields at ptr+4 and\nptr+6 before validating that the token is at least GSS_KRB5_TOK_HDR_LEN\n(16) bytes long, and its rotate_left() helper passes buf->len - base\nto xdr_buf_subsegment() without verifying that base <= buf->len. When\na caller hands in a sub-16-byte token, or a token whose declared len\nleaves base past the end of the buffer, three distinct failures follow:\n\n    gss_krb5_unwrap_v2(offset, len, buf)\n      ptr = buf->head[0].iov_base + offset\n      ec  = *(ptr + 4)              /* OOB read on short head */\n      rrc = *(ptr + 6)              /* OOB read on short head */\n      rotate_left(offset + 16, buf, rrc)\n        xdr_buf_subsegment(buf, &subbuf,\n                           base, buf->len - base)   /* u32 wrap when base > len */\n        _rotate_left(&subbuf, shift)\n          shift %= buf->len         /* divide-by-zero when base == len */\n\nAfter decryption, the cleanup arithmetic has the same shape:\n\n    movelen = min_t(unsigned int, buf->head[0].iov_len, len);\n    movelen -= offset + GSS_KRB5_TOK_HDR_LEN + headskip;\n    BUG_ON(offset + GSS_KRB5_TOK_HDR_LEN + headskip + movelen >\n                                            buf->head[0].iov_len);\n\nThe BUG_ON re-adds the value just subtracted, so it reduces to\nmin(A, B) > A and is permanently false; it cannot catch the unsigned\nunderflow of movelen, which then drives a ~UINT_MAX-byte memmove().\n\nAdd four defense-in-depth guards inside the unwrap core so it is safe\nregardless of what its callers validate:\n\n  - reject tokens with len - offset < GSS_KRB5_TOK_HDR_LEN before\n    touching ptr+4/ptr+6;\n  - bail from rotate_left() when buf->len <= base, covering both the\n    underflow and zero-length cases;\n  - return early from _rotate_left() when buf->len is zero, so the\n    shift %= buf->len modulo cannot fault;\n  - replace the dead BUG_ON with a live check that returns\n    GSS_S_DEFECTIVE_TOKEN before the movelen subtraction."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - gss_krb5_unwrap_v2() is reached from nfsd RPCSEC_GSS privacy unwrap (svcauth_gss_accept → svcauth_gss_unwrap_priv → gss_unwrap) on TCP/2049 and from the NFS client gss_unwrap_resp_priv() path on a krb5p Reply, so a remote RPCSEC_GSS peer delivers the crafted wrap token over the network.\nAC:L - A single crafted RPCSEC_GSS DATA/Reply with a sub-16-byte wrap token (KG2_TOK_WRAP, sealed flags, non-zero RRC) deterministically hits the pre-decrypt ptr+4/ptr+6 reads, rotate_left() u32 wrap, and shift%=0 divide-by-zero; no race or attacker-uncontrollable layout is required.\nPR:N - A malicious NFS server on an existing krb5p session needs no account or capability on the victim client to send the crafted Reply into gss_unwrap_resp_priv(). That client-victim path is the highest-severity reachability and requires no privileges on the target.\nUI:N - nfsd unwraps the Call in the service thread with no local user action. On the client, gss_unwrap_resp_priv() runs automatically from the RPC receive path once an NFS/RPCSEC_GSS mount exists; no additional mount, click, or open is required at attack time.\nS:U - The out-of-bounds accesses, divide-by-zero, and underflowed memmove corrupt host kernel SUNRPC/GSS state on the machine processing the RPC. This is ordinary same-host kernel impact, not a VM escape, IOMMU bypass, or other changed-scope boundary.\nC:H - Short tokens make gss_krb5_unwrap_v2() read EC/RRC past the token, and the dead BUG_ON lets unsigned movelen underflow into a ~UINT_MAX-byte memmove() that copies kernel memory beyond the receive head; that unbounded read is C:H per kernel CNA memory-corruption guidance.\nI:H - The same underflowed memmove() writes near 4GiB through the RPC receive head, an out-of-bounds write exploitable for control-flow hijack. rotate_left() also ignores xdr_buf_subsegment() failure after u32 wrap and then writes through a subbuf whose length has wrapped.\nA:H - _rotate_left() does shift %= buf->len on a zero-length subbuffer (header-only token at the XDR boundary), a divide-by-zero oops/panic; the UINT_MAX memmove and wrapped-length rotate loop hang or oops nfsd/rpciod, and the attacker can repeat the RPC to deny service."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sunrpc/auth_gss/gss_krb5_wrap.c"],"versions":[{"version":"de9c17eb4a912c9028f7b470eb80815144883b26","lessThan":"299d281c7225ded15b28cb861a98d818d82787fc","status":"affected","versionType":"git"},{"version":"de9c17eb4a912c9028f7b470eb80815144883b26","lessThan":"84ddbc8d084c0251d534f14f5d1a7da05be56404","status":"affected","versionType":"git"},{"version":"de9c17eb4a912c9028f7b470eb80815144883b26","lessThan":"075d7cfc4df8c54cb202ba8b28420370c03ba9b6","status":"affected","versionType":"git"},{"version":"de9c17eb4a912c9028f7b470eb80815144883b26","lessThan":"f2591660e0eb263c9415bf0d0bb1b111e62df7a4","status":"affected","versionType":"git"},{"version":"de9c17eb4a912c9028f7b470eb80815144883b26","lessThan":"dddcb0f4b7e27fac16a78ea9a1c8ec2e8a241087","status":"affected","versionType":"git"},{"version":"de9c17eb4a912c9028f7b470eb80815144883b26","lessThan":"806584a4b67a7233870c33e5b8f872e76dd02988","status":"affected","versionType":"git"},{"version":"de9c17eb4a912c9028f7b470eb80815144883b26","lessThan":"a7894e10572d53eb10109b8d07459cc8d3435811","status":"affected","versionType":"git"},{"version":"de9c17eb4a912c9028f7b470eb80815144883b26","lessThan":"6959297aaa9572783d620a226d73c3fb94494888","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sunrpc/auth_gss/gss_krb5_wrap.c"],"versions":[{"version":"2.6.35","status":"affected"},{"version":"0","lessThan":"2.6.35","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.35","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/299d281c7225ded15b28cb861a98d818d82787fc"},{"url":"https://git.kernel.org/stable/c/84ddbc8d084c0251d534f14f5d1a7da05be56404"},{"url":"https://git.kernel.org/stable/c/075d7cfc4df8c54cb202ba8b28420370c03ba9b6"},{"url":"https://git.kernel.org/stable/c/f2591660e0eb263c9415bf0d0bb1b111e62df7a4"},{"url":"https://git.kernel.org/stable/c/dddcb0f4b7e27fac16a78ea9a1c8ec2e8a241087"},{"url":"https://git.kernel.org/stable/c/806584a4b67a7233870c33e5b8f872e76dd02988"},{"url":"https://git.kernel.org/stable/c/a7894e10572d53eb10109b8d07459cc8d3435811"},{"url":"https://git.kernel.org/stable/c/6959297aaa9572783d620a226d73c3fb94494888"}],"title":"SUNRPC: harden gss_krb5_unwrap_v2 against short tokens","x_generator":{"engine":"bippy-1.2.0"}}}}