CVE-2026-89538
Received Received - Intake

Buffer Overflow in Linux Kernel SUNRPC

Vulnerability report for CVE-2026-89538, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field gss_krb5_unwrap_v2() sets buf->len to a logical length, which can be much smaller than head[0].iov_len (the allocated receive-page capacity). It then calls xdr_buf_trim() with a trim length derived from the 16-bit "extra count" (ec) field in the Kerberos v2 token header. The ec field is authenticated by the post-decrypt memcmp() against the encrypted header copy, so a randomly-mutated value is rejected. However, any peer holding a valid GSS context can legitimately encrypt a token whose ec exceeds the plaintext length. Per RFC 4121, such a token is structurally malformed. Although xdr_buf_trim() now clamps the buf->len subtraction to avoid unsigned underflow, the buffer is still left in a semantically invalid state (zero length, inconsistent iov lengths) when ec is oversized. Reject these tokens before calling xdr_buf_trim(), giving callers a well-defined GSS_S_DEFECTIVE_TOKEN error and keeping the xdr_buf internally consistent. The wrapped blob begins at a nonzero offset -- both callers pass len as offset + opaque_len -- so buf->len still counts the offset bytes that precede the blob. Compare the trim length against the remaining wrapped segment, buf->len - offset, rather than the whole buffer; comparing against buf->len alone leaves an offset-wide window in which an oversized ec passes the test and xdr_buf_trim() cuts into the bytes ahead of the blob.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves the SUNRPC component rejecting malformed Kerberos v2 wrap tokens with an oversized 'ec' field. The issue occurs when the token's extra count field exceeds the plaintext length, causing xdr_buf_trim() to leave the buffer in an invalid state with zero length and inconsistent iov lengths. The fix ensures tokens are rejected before processing to maintain buffer consistency.

Detection Guidance

This vulnerability is specific to the Linux kernel's SUNRPC implementation handling Kerberos v2 wrap tokens. Detection requires checking kernel logs for GSS-related errors or examining network traffic for malformed Kerberos v2 tokens. No direct commands are provided in the context to detect this issue.

Impact Analysis

An attacker with a valid GSS context could exploit this to send malformed tokens, potentially causing denial-of-service conditions or memory corruption in systems using SUNRPC with Kerberos authentication. This may lead to crashes or unpredictable behavior in affected applications.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it pertains to a specific kernel-level issue in SUNRPC's handling of Kerberos v2 wrap tokens. Compliance impacts would depend on system configuration and use of affected features, but the vulnerability itself is unrelated to data protection or privacy requirements.

Mitigation Strategies

Update the Linux kernel to a patched version that includes the fix for this vulnerability. Monitor kernel logs for GSS_S_DEFECTIVE_TOKEN errors which may indicate exploitation attempts. Ensure all systems using SUNRPC with Kerberos authentication are updated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89538. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart