CVE-2026-89550
Received Received - Intake

Kernel SUNRPC krb5 Token Length Validation Flaw

Vulnerability report for CVE-2026-89550, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svcauth_gss: enforce krb5 token minimum length svcauth_gss_unwrap_priv() validates only an upper bound on the wire-supplied opaque length before handing the buffer to gss_unwrap(): if (len > xdr_stream_remaining(xdr)) goto unwrap_failed; offset = xdr_stream_pos(xdr); ... maj_stat = gss_unwrap(ctx, offset, offset + len, buf); The wire value `len` flows unchanged as the upper bound into the krb5 unwrap path, so a len in [0, 16] passes this check and is handed to gss_unwrap(). For a krb5 v2 context that lands in gss_krb5_unwrap_v2(), which reads the 16-byte RFC 4121 token header fields at ptr+4 and ptr+6 and then calls rotate_left() before any integrity check. With a sub-header length the header reads run past the token, and _rotate_left()'s `shift %= buf->len` path can divide by zero when buf->len has been driven to zero by the truncated token. A header-only token (len == 16) is equally invalid: with a non-zero RRC field and the opaque blob ending at the XDR buffer boundary, rotate_left() builds a zero-length subbuffer, reaching the same division. Reject the token at the server entry point before it reaches the krb5 unwrap core. A valid sealed RFC 4121 token must contain the 16-byte header plus at least some encrypted payload. Fix by adding a minimum-length check immediately after the existing upper-bound check: if (len <= GSS_KRB5_TOK_HDR_LEN) goto unwrap_failed;

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux_kernel linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves insufficient validation of SUNRPC GSS krb5 tokens. The issue occurs when svcauth_gss_unwrap_priv() fails to enforce a minimum token length before processing. A token with length between 0 and 16 bytes bypasses initial checks and reaches gss_unwrap(), where it can trigger a division by zero in rotate_left() due to a zero-length subbuffer. The fix adds a minimum length check to reject invalid tokens at the server entry point.

Detection Guidance

This vulnerability affects the Linux kernel's SUNRPC GSS authentication. Detection requires checking kernel versions and examining RPC services using krb5 authentication. Inspect running services with 'systemctl list-units --type=service | grep rpc' and verify kernel logs for RPC-related errors. No specific commands are provided in the context.

Impact Analysis

This vulnerability could allow an attacker to cause a denial of service by crashing the Linux kernel via a crafted krb5 token. Systems using SUNRPC with GSSAPI authentication for NFS or other services may be affected. The impact is limited to kernel crashes and potential service disruption rather than data theft or privilege escalation.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it is a low-level kernel issue related to memory corruption in SUNRPC GSSAPI authentication. Compliance impacts would only occur if exploitation led to unauthorized data access or service disruption, which is not described in the provided context.

Mitigation Strategies

Apply the kernel patch that adds a minimum-length check for krb5 tokens. Update the Linux kernel to a version containing the fix. Disable SUNRPC services using krb5 authentication if not required. Monitor kernel logs for RPC-related errors post-update.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89550. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart