CVE-2026-89537
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: Reject short RFC 4121 MIC tokens in gsskrb5verifymicv2
gsskrb5verifymicv2() reads the token ID at ptr[0..1], the flags
byte at ptr[2], and padding at ptr[3..7], then passes
ptr + GSSKRB5TOKHDRLEN and cksumlen to gsskrb5micbuild_sg().
None of these accesses check read_token->len first.
The minimum safe token size is GSSKRB5TOKHDRLEN (16) plus
ctx->krb5e->cksum_len (12-24, depending on the enctype). All callers
accept shorter tokens from the wire:
- gssunwrapresp_integ() enforces only an upper bound
(offset + len <= rcv_buf->len) before allocating
mic.data = kmalloc(len) and passing it to gssverifymic().
A malicious NFS server can therefore supply a short checksum
opaque, producing a small slab allocation that the Kerberos MIC
verifier reads past.
- gssvalidate() enforces only len <= RPCMAXAUTHSIZE (400)
before passing the wire-supplied length to
gssvalidateseqnomic(), which constructs a mic xdrnetobj
and calls gssverifymic().
- svcauthgssverify_header() enforces only
checksum.len >= XDR_UNIT (4 bytes) before dispatching to
gssverifymic().
- svcauthgssunwrap_integ() checks only that the checksum fits
in gsd->gsd_scratch.
Add a length guard at the top of gsskrb5verifymicv2(), before any
ptr[] access or scatterlist construction. Well-formed MIC tokens from
gsskrb5getmicv2() already have exactly GSSKRB5TOKHDRLEN +
cksum_len bytes, so valid traffic is unaffected.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/7a946b2e7207f968902f2147ab9b30726f82f7ab, https://git.kernel.org/stable/c/b94f6719dcd9f7a609bc5f459f85795900e77d25, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89537.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89537, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git