{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89551","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.723Z","datePublished":"2026-09-11T19:44:25.327Z","dateUpdated":"2026-09-14T12:00:54.700Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:00:54.700Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow\n\nxdr_buf_trim() trims `len` bytes from the tail of an xdr_buf by\nwalking the tail, pages, and head iovecs.  Each per-section step\nuses min_t() so it never removes more bytes than that section\nholds, but the final accounting at the fix_len label subtracts the\ntotal bytes actually consumed from buf->len without any clamp:\n\n    fix_len:\n            buf->len -= (len - trim);\n\nWhen the caller has set buf->len to a value smaller than the sum\nof the iov_lens, (len - trim) can exceed buf->len and the unsigned\nsubtraction wraps to near UINT_MAX.  gss_krb5_unwrap_v2() reaches\nxdr_buf_trim() in exactly that state:\n\n    buf->head[0].iov_len -= GSS_KRB5_TOK_HDR_LEN + headskip;\n    buf->len = len - (GSS_KRB5_TOK_HDR_LEN + headskip);\n    xdr_buf_trim(buf, ec + GSS_KRB5_TOK_HDR_LEN + tailskip);\n\nbuf->len is a small wire-derived value while the iov_lens are at\npage scale, so the per-section loops legitimately consume far more\nbytes than buf->len records.  The wrapped buf->len then propagates\nas the authoritative stream bound into every downstream XDR\ndecoder.\n\nFix by clamping the decrement so buf->len bottoms out at zero:\n\n    buf->len -= min_t(unsigned int, buf->len, len - trim);\n\nOn the normal path where the iov_lens sum to buf->len, (len - trim)\nis always <= buf->len and the result is identical to before.  No\ncallers change behavior outside the underflow case."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - xdr_buf_trim() is reached from nfsd RPCSEC_GSS privacy unwrap on TCP/2049 (svcauth_gss_unwrap_priv → gss_unwrap → gss_krb5_unwrap_v2) and from the NFS client's gss_unwrap_resp_priv() on every krb5p reply, so a remote NFS peer delivers the wrap token over the network.\nAC:L - A peer holding the GSS session keys can encrypt a RFC 4121 wrap token so that after decrypt, buf->len is a small wire-derived value while iov_lens remain page-scale; xdr_buf_trim() then subtracts more than buf->len and wraps, with no race or layout outside attacker control.\nPR:N - A malicious or compromised NFS server that already shares a krb5p GSS context needs no account or capability on the victim client; ordinary krb5p replies and NFSv4.0 GSS callbacks are processed without local privileges on that host.\nUI:N - Once a krb5p NFS mount exists, the client unwraps every privacy-protected reply and NFSv4.0 GSS callback with no further mount, click, or open; idle revalidations and server-driven callbacks are sufficient.\nS:U - The wrapped buf->len and subsequent XDR decode run in the host kernel that processed the RPC and do not cross a VM, IOMMU, or sandbox boundary.\nC:H - The underflowed buf->len (~UINT_MAX) becomes the authoritative stream bound, and on nfsd xdr->nwords also underflows via saved_len - buf->len, so later xdr_read_pages/xdr_shrink_bufhead and NFS XDR decoders read far past the receive buffer into adjacent kernel memory.\nI:H - xdr_shrink_bufhead() calls xdr_buf_head_shift_right() with a near-UINT_MAX length derived from the wrapped buf->len, and garbage xdr_stream_pos values can index the svc pages[] array out of bounds, an out-of-bounds write exploitable for control-flow hijacking.\nA:H - Those unbounded XDR copies and the inconsistent xdr_buf (wrapped length versus iov_lens) oops or panic nfsd or the NFS client, and the peer can repeat the request at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sunrpc/xdr.c"],"versions":[{"version":"4c190e2f913f038c9c91ee63b59cd037260ba353","lessThan":"a3d77bcd974b8625d16bddf448cb3a1b5e37049c","status":"affected","versionType":"git"},{"version":"4c190e2f913f038c9c91ee63b59cd037260ba353","lessThan":"fa16bbe987b47e771e52eeb1b4540f18d92496ac","status":"affected","versionType":"git"},{"version":"4c190e2f913f038c9c91ee63b59cd037260ba353","lessThan":"a924ac4c78afab71bf82641afa3b62e0c4a8b55e","status":"affected","versionType":"git"},{"version":"4c190e2f913f038c9c91ee63b59cd037260ba353","lessThan":"4bf59cb0ea5b0ddfbc46a1dc2fa78fc8b9986ce4","status":"affected","versionType":"git"},{"version":"4c190e2f913f038c9c91ee63b59cd037260ba353","lessThan":"e6267cccd7b05cc514e57f2160aa8db85f5c2701","status":"affected","versionType":"git"},{"version":"4c190e2f913f038c9c91ee63b59cd037260ba353","lessThan":"ad0cce80d4af2f74674e8b635d97aa3880e83da8","status":"affected","versionType":"git"},{"version":"4c190e2f913f038c9c91ee63b59cd037260ba353","lessThan":"85e9602650e9df07190abe817cee3b4d9bc3df17","status":"affected","versionType":"git"},{"version":"4c190e2f913f038c9c91ee63b59cd037260ba353","lessThan":"3f491306dcb673ff5e78e1044ba450c58978774e","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sunrpc/xdr.c"],"versions":[{"version":"3.9","status":"affected"},{"version":"0","lessThan":"3.9","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a3d77bcd974b8625d16bddf448cb3a1b5e37049c"},{"url":"https://git.kernel.org/stable/c/fa16bbe987b47e771e52eeb1b4540f18d92496ac"},{"url":"https://git.kernel.org/stable/c/a924ac4c78afab71bf82641afa3b62e0c4a8b55e"},{"url":"https://git.kernel.org/stable/c/4bf59cb0ea5b0ddfbc46a1dc2fa78fc8b9986ce4"},{"url":"https://git.kernel.org/stable/c/e6267cccd7b05cc514e57f2160aa8db85f5c2701"},{"url":"https://git.kernel.org/stable/c/ad0cce80d4af2f74674e8b635d97aa3880e83da8"},{"url":"https://git.kernel.org/stable/c/85e9602650e9df07190abe817cee3b4d9bc3df17"},{"url":"https://git.kernel.org/stable/c/3f491306dcb673ff5e78e1044ba450c58978774e"}],"title":"SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow","x_generator":{"engine":"bippy-1.2.0"}}}}