-

CVE-2026-89539

SUNRPC: reject duplicate CREDS_VALUE options

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: reject duplicate CREDS_VALUE options

gssx_dec_option_array() walks the wire-supplied option array and, for
every entry whose name matches CREDS_VALUE, calls
gssx_dec_linux_creds() on the same struct svc_cred. That helper
unconditionally installs a fresh groups_alloc() result into
creds->cr_group_info without releasing whatever pointer was already
there:

    for (i = 0; i < count; i++) {
        ... decode name ...
        if (length == sizeof(CREDS_VALUE) &&
            memcmp(p, CREDS_VALUE, sizeof(CREDS_VALUE)) == 0) {
            err = gssx_dec_linux_creds(xdr, creds);
            ...
        }
    }

A reply that carries two CREDS_VALUE entries therefore overwrites
cr_group_info on the second iteration and orphans the group_info
allocated by the first call. The earlier free_creds path only
releases the last cr_group_info via free_svc_cred(), so the first
allocation's refcount stays at one and its kvmalloc-backed storage
is leaked. No in-tree caller of gssp_accept_sec_context_upcall()
expects more than one CREDS_VALUE per reply.

Fix by tracking whether a CREDS_VALUE option has already been
decoded and returning -EINVAL on any subsequent match, so the
free_creds path releases the single group_info that was installed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1d658336b05f8697d6445834f8867f8ad5e4f735
Version < f615b884310bf82d0014e3b5a92eb9aa88146685
Status affected
Version 1d658336b05f8697d6445834f8867f8ad5e4f735
Version < 7a1d0501cbb962beba23377035d667bf3c1726ee
Status affected
Version 1d658336b05f8697d6445834f8867f8ad5e4f735
Version < 9d94f046b23de0f77849ea69133063c949297e30
Status affected
Version 1d658336b05f8697d6445834f8867f8ad5e4f735
Version < 2e4ce62385c1b8a887c5370af058ac7b52a8eaf9
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.10
Status affected
Version 0
Version < 3.10
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f615b884310bf82d0014e3b5a92eb9aa88146685
https://git.kernel.org/stable/c/7a1d0501cbb962beba23377035d667bf3c1726ee
https://git.kernel.org/stable/c/9d94f046b23de0f77849ea69133063c949297e30
https://git.kernel.org/stable/c/2e4ce62385c1b8a887c5370af058ac7b52a8eaf9