CVE-2026-89537
Received Received - Intake

Buffer Overflow in Linux Kernel SUNRPC

Vulnerability report for CVE-2026-89537, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2 gss_krb5_verify_mic_v2() reads the token ID at ptr[0..1], the flags byte at ptr[2], and padding at ptr[3..7], then passes ptr + GSS_KRB5_TOK_HDR_LEN and cksum_len to gss_krb5_mic_build_sg(). None of these accesses check read_token->len first. The minimum safe token size is GSS_KRB5_TOK_HDR_LEN (16) plus ctx->krb5e->cksum_len (12-24, depending on the enctype). All callers accept shorter tokens from the wire: - gss_unwrap_resp_integ() enforces only an upper bound (offset + len <= rcv_buf->len) before allocating mic.data = kmalloc(len) and passing it to gss_verify_mic(). A malicious NFS server can therefore supply a short checksum opaque, producing a small slab allocation that the Kerberos MIC verifier reads past. - gss_validate() enforces only len <= RPC_MAX_AUTH_SIZE (400) before passing the wire-supplied length to gss_validate_seqno_mic(), which constructs a mic xdr_netobj and calls gss_verify_mic(). - svcauth_gss_verify_header() enforces only checksum.len >= XDR_UNIT (4 bytes) before dispatching to gss_verify_mic(). - svcauth_gss_unwrap_integ() checks only that the checksum fits in gsd->gsd_scratch. Add a length guard at the top of gss_krb5_verify_mic_v2(), before any ptr[] access or scatterlist construction. Well-formed MIC tokens from gss_krb5_get_mic_v2() already have exactly GSS_KRB5_TOK_HDR_LEN + cksum_len bytes, so valid traffic is unaffected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper handling of RFC 4121 MIC tokens in the gss_krb5_verify_mic_v2 function. The issue occurs because the function reads token data without first verifying the token length, allowing short tokens to be processed. This can lead to buffer over-reads when the Kerberos MIC verifier reads past the allocated memory.

Detection Guidance

This vulnerability involves improper handling of RFC 4121 MIC tokens in the Linux kernel's SUNRPC implementation. Detection requires checking for short token lengths in Kerberos authentication traffic. Monitor kernel logs for gss_krb5_verify_mic_v2 errors or unusual NFS traffic patterns. Use tcpdump or Wireshark to inspect NFS traffic for abnormally small checksum fields in Kerberos MIC tokens.

Impact Analysis

An attacker could exploit this to cause memory corruption or crashes by sending maliciously crafted NFS traffic with short checksums. This may lead to denial-of-service conditions or potential unauthorized access if combined with other exploits.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized data access or integrity breaches in systems using NFS with Kerberos authentication. A malicious actor could exploit the short token handling to bypass security checks, leading to unauthorized data access or tampering. This may violate requirements for secure data transmission and integrity in both GDPR (e.g., Article 32) and HIPAA (e.g., Security Rule).

Mitigation Strategies

Apply the Linux kernel patch that adds length validation in gss_krb5_verify_mic_v2(). Update to a kernel version containing the fix. If patching is not immediately possible, restrict NFS exports to trusted servers only and disable Kerberos authentication for NFS if feasible. Monitor for exploitation attempts in logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89537. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart