CVE-2026-89541
Received Received - Intake

Buffer Overflow in Linux Kernel SUNRPC

Vulnerability report for CVE-2026-89541, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_unwrap_resp_priv length checks gss_unwrap_resp_priv() validates the RPCSEC_GSS opaque length with offset = (u8 *)(p) - (u8 *)head->iov_base; if (offset + opaque_len > rcv_buf->len) goto unwrap_failed; maj_stat = gss_unwrap(ctx->gc_gss_ctx, offset, offset + opaque_len, rcv_buf); Both operands are u32 and the sum is computed in u32. A reply with opaque_len near 0xffffffff makes offset + opaque_len wrap to a small value that is below rcv_buf->len, so the bound check passes and gss_unwrap() is called with end < begin. The check also lacks a lower bound, so any opaque_len in [0, GSS_KRB5_TOK_HDR_LEN) is accepted and forwarded to gss_krb5_unwrap_v2(), whose pre-decrypt header reads at ptr+4 and ptr+6 then run past the token. A krb5p NFS server returning a crafted RPCSEC_GSS reply can drive the client into out-of-bounds reads in gss_krb5_unwrap_v2() and the rotate_left() loop that follows. Fix by replacing the single combined check with three guards that are safe in u32 arithmetic and that enforce the RFC 4121 minimum outer token length: if (offset > rcv_buf->len) goto unwrap_failed; if (opaque_len > rcv_buf->len - offset) goto unwrap_failed; if (opaque_len < GSS_KRB5_TOK_HDR_LEN) goto unwrap_failed; The first guard makes the subtraction in the second guard unconditionally safe; offset is derived from a successful xdr_inline_decode() in the head kvec, so in practice it already satisfies the bound. The floor mirrors the server-side check added in commit 5b757c2e57a5 ("SUNRPC: svcauth_gss: enforce krb5 token minimum length").

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a weakness in the SUNRPC subsystem's gss_unwrap_resp_priv function. It allows an attacker to craft a malicious RPCSEC_GSS reply that causes out-of-bounds memory reads in the client's kernel. The issue stems from improper length checks that can wrap around due to unsigned 32-bit integer arithmetic, bypassing security checks and leading to memory corruption.

Detection Guidance

This vulnerability is specific to the Linux kernel's SUNRPC implementation and requires kernel-level inspection. Detection involves checking kernel versions and SUNRPC code paths. Use commands like 'uname -a' to check kernel version and 'dmesg | grep -i sunrpc' to monitor for related errors. However, no direct detection commands are provided in the context.

Impact Analysis

If exploited, this vulnerability could allow an attacker with network access to a vulnerable NFS server to crash the client system or potentially execute arbitrary code with kernel privileges. Systems using NFS with Kerberos authentication (krb5p) are particularly at risk. The impact includes denial of service and potential unauthorized access to system memory.

Mitigation Strategies

Apply the latest kernel patches from your Linux distribution to ensure the fix for SUNRPC gss_unwrap_resp_priv is included. Monitor vendor advisories for updates. Disable NFS with krb5p security if possible until patched. Restart services after applying updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89541. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart