9.8

CVE-2026-89541

SUNRPC: harden gss_unwrap_resp_priv length checks

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: harden gss_unwrap_resp_priv length checks

gss_unwrap_resp_priv() validates the RPCSEC_GSS opaque length with

    offset = (u8 *)(p) - (u8 *)head->iov_base;
    if (offset + opaque_len > rcv_buf->len)
            goto unwrap_failed;
    maj_stat = gss_unwrap(ctx->gc_gss_ctx, offset,
                          offset + opaque_len, rcv_buf);

Both operands are u32 and the sum is computed in u32. A reply with
opaque_len near 0xffffffff makes offset + opaque_len wrap to a small
value that is below rcv_buf->len, so the bound check passes and
gss_unwrap() is called with end < begin. The check also lacks a
lower bound, so any opaque_len in [0, GSS_KRB5_TOK_HDR_LEN) is
accepted and forwarded to gss_krb5_unwrap_v2(), whose pre-decrypt
header reads at ptr+4 and ptr+6 then run past the token.

A krb5p NFS server returning a crafted RPCSEC_GSS reply can drive
the client into out-of-bounds reads in gss_krb5_unwrap_v2() and the
rotate_left() loop that follows.

Fix by replacing the single combined check with three guards that
are safe in u32 arithmetic and that enforce the RFC 4121 minimum
outer token length:

    if (offset > rcv_buf->len)
            goto unwrap_failed;
    if (opaque_len > rcv_buf->len - offset)
            goto unwrap_failed;
    if (opaque_len < GSS_KRB5_TOK_HDR_LEN)
            goto unwrap_failed;

The first guard makes the subtraction in the second guard
unconditionally safe; offset is derived from a successful
xdr_inline_decode() in the head kvec, so in practice it already
satisfies the bound. The floor mirrors the server-side check added
in commit 5b757c2e57a5 ("SUNRPC: svcauth_gss: enforce krb5 token
minimum length").
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf
Version < 3691c4b3488d8ca046b9941e5be30c626dbbbb50
Status affected
Version 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf
Version < 85fa6b12e8f439739ac36ef2aad925f37c8b976a
Status affected
Version 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf
Version < 401f6a5b338d05bb1069ad814d9f77e3c367854f
Status affected
Version 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf
Version < 81fd7654a8429718adfcb2a7e03496077f547ed0
Status affected
Version 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf
Version < 89a15a50f84d32d4b99db86f957427fcbe20a99a
Status affected
Version 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf
Version < ebcbd2523a8524c3d24e111cdbed8e271d910269
Status affected
Version 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf
Version < d395c30d570ca6168f0297b191709927d1258273
Status affected
Version 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf
Version < 87831b92112c81db251d46756d65daa4f91af6a2
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.15
Status affected
Version 0
Version < 2.6.15
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.388
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/89a15a50f84d32d4b99db86f957427fcbe20a99a
https://git.kernel.org/stable/c/ebcbd2523a8524c3d24e111cdbed8e271d910269
https://git.kernel.org/stable/c/d395c30d570ca6168f0297b191709927d1258273
https://git.kernel.org/stable/c/87831b92112c81db251d46756d65daa4f91af6a2
https://git.kernel.org/stable/c/3691c4b3488d8ca046b9941e5be30c626dbbbb50
https://git.kernel.org/stable/c/401f6a5b338d05bb1069ad814d9f77e3c367854f
https://git.kernel.org/stable/c/81fd7654a8429718adfcb2a7e03496077f547ed0
https://git.kernel.org/stable/c/85fa6b12e8f439739ac36ef2aad925f37c8b976a