9.8

CVE-2026-89542

SUNRPC: harden gss_krb5_unwrap_v2 against short tokens

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: harden gss_krb5_unwrap_v2 against short tokens

gss_krb5_unwrap_v2() reads the EC and RRC header fields at ptr+4 and
ptr+6 before validating that the token is at least GSS_KRB5_TOK_HDR_LEN
(16) bytes long, and its rotate_left() helper passes buf->len - base
to xdr_buf_subsegment() without verifying that base <= buf->len. When
a caller hands in a sub-16-byte token, or a token whose declared len
leaves base past the end of the buffer, three distinct failures follow:

    gss_krb5_unwrap_v2(offset, len, buf)
      ptr = buf->head[0].iov_base + offset
      ec  = *(ptr + 4)              /* OOB read on short head */
      rrc = *(ptr + 6)              /* OOB read on short head */
      rotate_left(offset + 16, buf, rrc)
        xdr_buf_subsegment(buf, &subbuf,
                           base, buf->len - base)   /* u32 wrap when base > len */
        _rotate_left(&subbuf, shift)
          shift %= buf->len         /* divide-by-zero when base == len */

After decryption, the cleanup arithmetic has the same shape:

    movelen = min_t(unsigned int, buf->head[0].iov_len, len);
    movelen -= offset + GSS_KRB5_TOK_HDR_LEN + headskip;
    BUG_ON(offset + GSS_KRB5_TOK_HDR_LEN + headskip + movelen >
                                            buf->head[0].iov_len);

The BUG_ON re-adds the value just subtracted, so it reduces to
min(A, B) > A and is permanently false; it cannot catch the unsigned
underflow of movelen, which then drives a ~UINT_MAX-byte memmove().

Add four defense-in-depth guards inside the unwrap core so it is safe
regardless of what its callers validate:

  - reject tokens with len - offset < GSS_KRB5_TOK_HDR_LEN before
    touching ptr+4/ptr+6;
  - bail from rotate_left() when buf->len <= base, covering both the
    underflow and zero-length cases;
  - return early from _rotate_left() when buf->len is zero, so the
    shift %= buf->len modulo cannot fault;
  - replace the dead BUG_ON with a live check that returns
    GSS_S_DEFECTIVE_TOKEN before the movelen subtraction.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version de9c17eb4a912c9028f7b470eb80815144883b26
Version < 299d281c7225ded15b28cb861a98d818d82787fc
Status affected
Version de9c17eb4a912c9028f7b470eb80815144883b26
Version < 84ddbc8d084c0251d534f14f5d1a7da05be56404
Status affected
Version de9c17eb4a912c9028f7b470eb80815144883b26
Version < 075d7cfc4df8c54cb202ba8b28420370c03ba9b6
Status affected
Version de9c17eb4a912c9028f7b470eb80815144883b26
Version < f2591660e0eb263c9415bf0d0bb1b111e62df7a4
Status affected
Version de9c17eb4a912c9028f7b470eb80815144883b26
Version < dddcb0f4b7e27fac16a78ea9a1c8ec2e8a241087
Status affected
Version de9c17eb4a912c9028f7b470eb80815144883b26
Version < 806584a4b67a7233870c33e5b8f872e76dd02988
Status affected
Version de9c17eb4a912c9028f7b470eb80815144883b26
Version < a7894e10572d53eb10109b8d07459cc8d3435811
Status affected
Version de9c17eb4a912c9028f7b470eb80815144883b26
Version < 6959297aaa9572783d620a226d73c3fb94494888
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.35
Status affected
Version 0
Version < 2.6.35
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.388
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/dddcb0f4b7e27fac16a78ea9a1c8ec2e8a241087
https://git.kernel.org/stable/c/806584a4b67a7233870c33e5b8f872e76dd02988
https://git.kernel.org/stable/c/a7894e10572d53eb10109b8d07459cc8d3435811
https://git.kernel.org/stable/c/6959297aaa9572783d620a226d73c3fb94494888
https://git.kernel.org/stable/c/075d7cfc4df8c54cb202ba8b28420370c03ba9b6
https://git.kernel.org/stable/c/299d281c7225ded15b28cb861a98d818d82787fc
https://git.kernel.org/stable/c/84ddbc8d084c0251d534f14f5d1a7da05be56404
https://git.kernel.org/stable/c/f2591660e0eb263c9415bf0d0bb1b111e62df7a4