{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89544","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.722Z","datePublished":"2026-09-11T19:44:20.424Z","dateUpdated":"2026-09-21T13:14:24.848Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-21T13:14:24.848Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: fix gssx_dec_option_array error path bugs\n\nFour coupled defects in the gssx XDR option-array decoder make the\nerror paths unsafe: a NULL deref in the caller, a refcount leak on\nthe decoded group_info, and a latent use-after-free that the leak\nfix would otherwise expose.\n\ngssx_dec_option_array() sets oa->count = 1 before allocating\noa->data.  If that allocation fails, -ENOMEM is returned with\noa->count == 1 and oa->data == NULL.  All other error paths jump\nto free_oa: which frees oa->data and NULLs it but also leaves\noa->count == 1.  The caller trusts the count:\n\n    gssp_accept_sec_context_upcall()\n      gssx_dec_accept_sec_context()\n        gssx_dec_option_array()        /* fails, count=1 data=NULL */\n      data = res.options.data[0].value /* NULL deref */\n\nIndependently, free_creds: releases the partially decoded svc_cred\nwith a bare kfree(creds).  gssx_dec_linux_creds() installs a\ngroups_alloc() result into creds->cr_group_info; that object is\nkvmalloc-backed and refcounted, and only put_group_info() reaches\nkvfree().  A plain kfree(creds) drops the wrapper and leaks the\ngroup_info allocation.\n\nThe natural fix for the leak is to call free_svc_cred(creds) before\nkfree(creds), but free_svc_cred() invokes put_group_info() on\ncreds->cr_group_info unconditionally when non-NULL.  The existing\nout_free_groups: path in gssx_dec_linux_creds() already called\ngroups_free() on that pointer without clearing it, so once\nfree_svc_cred() is wired in, the subsequent put_group_info() would\ntouch freed memory.\n\nFix all four together:\n\n  - Move the oa->count = 1 assignment below the oa->data allocation\n    so it is never set when oa->data is NULL.\n  - Reset oa->count to 0 at free_oa: so count and data stay\n    coherent and the caller sees an empty option array.\n  - Call free_svc_cred(creds) before kfree(creds) at free_creds:\n    so the refcounted cr_group_info is released.  free_svc_cred()\n    either NULL-guards each field explicitly (cr_group_info has\n    an if() check) or delegates to a helper that is NULL-safe\n    itself (kfree for the string fields, gss_mech_put() which\n    guards with if(gm) at gss_mech_switch.c:342), so it is safe\n    to call on a partially decoded svc_cred where only\n    cr_uid/cr_gid/cr_group_info have been written and everything\n    else is zero from kzalloc.\n  - In gssx_dec_linux_creds()'s out_free_groups: path, release\n    cr_group_info with put_group_info() rather than groups_free()\n    so the teardown matches free_svc_cred()'s refcount-aware path,\n    and clear the pointer so a later free_svc_cred() on the same\n    creds does not release it a second time."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The decoder runs only as a consequence of an RPCSEC_GSS_INIT/CONTINUE_INIT Call to in-kernel nfsd (and other SUNRPC servers such as lockd) on the network, typically TCP/2049. A remote client drives svcauth_gss_proxy_init() → gssp_accept_sec_context_upcall() → gssx_dec_option_array(); the attacker’s reach is purely over the network.\nAC:L - Any allocation or XDR error after oa->count is set to 1 leaves count=1 with data=NULL, and the caller always indexes res.options.data[0]. The attacker can induce those failures by flooding pre-auth GSS_INIT upcalls that each pin 256 KB of receive pages (especially under memcg-limited nfsd) and by driving large group-list replies, so success does not depend on conditions beyond their control.\nPR:N - svcauth_gss_proxy_init() runs from svcauth_gss_proc_init() on the first RPCSEC_GSS handshake leg, before the kernel has validated any Kerberos ticket. The upcall and option-array decode execute for an unauthenticated NFS client; no local account or prior credential on the server is required.\nUI:N - The crash is triggered entirely by an inbound RPC to an already-running nfsd/SUNRPC service thread. No administrator or end-user action such as mounting a filesystem or opening a file is required.\nS:U - The NULL dereference and group_info leak occur inside the host kernel’s SUNRPC/GSS code. Impact stays within that kernel’s security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:N - With oa->count==1 and oa->data==NULL, gssp_accept_sec_context_upcall() does &res.options.data[0].value, a NULL+small-offset load that faults on the unmapped zero page. No kernel memory is returned to the attacker; unlike a UAF, freed object contents are never read.\nI:N - The faulting access is a pure NULL-pointer dereference with no kernel write. The put_group_info() UAF described in the fix is only latent: the unpatched free_creds path kfree()s the svc_cred wrapper without touching cr_group_info, so the dangling pointer is not used.\nA:H - The NULL dereference oopses the nfsd (or lockd) thread and panics the host where panic_on_oops is set, which is typical on NAS/appliance NFS servers. The same error path also leaks the kvmalloc-backed group_info, and the crash can be repeated to take down SUNRPC service threads."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sunrpc/auth_gss/gss_rpc_xdr.c"],"versions":[{"version":"3cfcfc102a5e57b021b786a755a38935e357797d","lessThan":"fb30241f7ccace372ee83017891549f23a715581","status":"affected","versionType":"git"},{"version":"3cfcfc102a5e57b021b786a755a38935e357797d","lessThan":"3ff45361e9469e85c0f86b8e7b82c63e50bab8ef","status":"affected","versionType":"git"},{"version":"3cfcfc102a5e57b021b786a755a38935e357797d","lessThan":"f85a83774d7f4e2ac71c0c384df0dfb6f7d0179a","status":"affected","versionType":"git"},{"version":"3cfcfc102a5e57b021b786a755a38935e357797d","lessThan":"5e9a94539b1ec17a89177d952badfd0d844d694a","status":"affected","versionType":"git"},{"version":"b97c37978ca825557d331c9012e0c1ddc0e42364","status":"affected","versionType":"git"},{"version":"bfa9d86d39a0fe4685f90c3529aa9bd62a9d97a8","status":"affected","versionType":"git"},{"version":"bb336cd8d5ecb69c430ebe3e7bcff68471d93fa8","status":"affected","versionType":"git"},{"version":"dd292e884c649f9b1c18af0ec75ca90b390cd044","status":"affected","versionType":"git"},{"version":"934212a623cbab851848b6de377eb476718c3e4c","status":"affected","versionType":"git"},{"version":"5e6013ae2c8d420faea553d363935f65badd32c3","status":"affected","versionType":"git"},{"version":"9806c2393cd2ab0a8e7bb9ffae02ce20e3112ec4","status":"affected","versionType":"git"},{"version":"996997d1fb2126feda550d6adcedcbd94911fc69","status":"affected","versionType":"git"},{"version":"4.19.311","lessThan":"4.20","status":"affected","versionType":"semver"},{"version":"5.4.273","lessThan":"5.5","status":"affected","versionType":"semver"},{"version":"5.10.214","lessThan":"5.11","status":"affected","versionType":"semver"},{"version":"5.15.153","lessThan":"5.16","status":"affected","versionType":"semver"},{"version":"6.1.83","lessThan":"6.2","status":"affected","versionType":"semver"},{"version":"6.6.23","lessThan":"6.7","status":"affected","versionType":"semver"},{"version":"6.7.11","lessThan":"6.8","status":"affected","versionType":"semver"},{"version":"6.8.2","lessThan":"6.9","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sunrpc/auth_gss/gss_rpc_xdr.c"],"versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19.311"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.273"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.214"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.153"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.83"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.23"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/fb30241f7ccace372ee83017891549f23a715581"},{"url":"https://git.kernel.org/stable/c/3ff45361e9469e85c0f86b8e7b82c63e50bab8ef"},{"url":"https://git.kernel.org/stable/c/f85a83774d7f4e2ac71c0c384df0dfb6f7d0179a"},{"url":"https://git.kernel.org/stable/c/5e9a94539b1ec17a89177d952badfd0d844d694a"}],"title":"SUNRPC: fix gssx_dec_option_array error path bugs","x_generator":{"engine":"bippy-1.2.0"}}}}