CVE-2026-89551
Received Received - Intake

Integer Underflow in Linux Kernel XDR Buffer Handling

Vulnerability report for CVE-2026-89551, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow xdr_buf_trim() trims `len` bytes from the tail of an xdr_buf by walking the tail, pages, and head iovecs. Each per-section step uses min_t() so it never removes more bytes than that section holds, but the final accounting at the fix_len label subtracts the total bytes actually consumed from buf->len without any clamp: fix_len: buf->len -= (len - trim); When the caller has set buf->len to a value smaller than the sum of the iov_lens, (len - trim) can exceed buf->len and the unsigned subtraction wraps to near UINT_MAX. gss_krb5_unwrap_v2() reaches xdr_buf_trim() in exactly that state: buf->head[0].iov_len -= GSS_KRB5_TOK_HDR_LEN + headskip; buf->len = len - (GSS_KRB5_TOK_HDR_LEN + headskip); xdr_buf_trim(buf, ec + GSS_KRB5_TOK_HDR_LEN + tailskip); buf->len is a small wire-derived value while the iov_lens are at page scale, so the per-section loops legitimately consume far more bytes than buf->len records. The wrapped buf->len then propagates as the authoritative stream bound into every downstream XDR decoder. Fix by clamping the decrement so buf->len bottoms out at zero: buf->len -= min_t(unsigned int, buf->len, len - trim); On the normal path where the iov_lens sum to buf->len, (len - trim) is always <= buf->len and the result is identical to before. No callers change behavior outside the underflow case.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in the Linux kernel's SUNRPC subsystem. The function xdr_buf_trim() can cause an integer underflow when trimming data from a buffer. The issue occurs when the buffer's length is smaller than the total data being removed, causing an unsigned integer wrap-around to a very large value. This corrupted length then affects downstream XDR decoders.

Detection Guidance

This vulnerability is specific to the Linux kernel's SUNRPC implementation and requires kernel-level inspection. Detection involves checking kernel logs for crashes or errors related to xdr_buf_trim() or SUNRPC operations. Commands like dmesg, journalctl -k, or checking for kernel oops messages may help identify issues.

Impact Analysis

The vulnerability could allow an attacker to corrupt kernel memory by triggering the integer underflow. This might lead to system crashes, privilege escalation, or other unintended behavior depending on how the affected code paths are used in your system.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA. It is a low-level kernel memory handling issue that could lead to buffer underflow and potential data corruption in SUNRPC operations. Compliance impact would only occur if this flaw caused unauthorized data access or integrity issues in systems handling sensitive data.

Mitigation Strategies

Apply the kernel patch that clamps buf->len to avoid underflow in xdr_buf_trim(). Update to a fixed kernel version where this issue is resolved. Monitor for SUNRPC-related crashes or errors post-update.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89551. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart