CVE-2026-89541
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: harden gssunwrapresp_priv length checks
gssunwrapresppriv() validates the RPCSECGSS opaque length with
offset = (u8 )(p) - (u8 )head->iov_base;
if (offset + opaquelen > rcvbuf->len)
goto unwrap_failed;
majstat = gssunwrap(ctx->gcgssctx, offset,
offset + opaquelen, rcvbuf);
Both operands are u32 and the sum is computed in u32. A reply with
opaquelen near 0xffffffff makes offset + opaquelen wrap to a small
value that is below rcv_buf->len, so the bound check passes and
gss_unwrap() is called with end < begin. The check also lacks a
lower bound, so any opaquelen in [0, GSSKRB5TOKHDR_LEN) is
accepted and forwarded to gsskrb5unwrap_v2(), whose pre-decrypt
header reads at ptr+4 and ptr+6 then run past the token.
A krb5p NFS server returning a crafted RPCSEC_GSS reply can drive
the client into out-of-bounds reads in gsskrb5unwrap_v2() and the
rotate_left() loop that follows.
Fix by replacing the single combined check with three guards that
are safe in u32 arithmetic and that enforce the RFC 4121 minimum
outer token length:
if (offset > rcv_buf->len)
goto unwrap_failed;
if (opaquelen > rcvbuf->len - offset)
goto unwrap_failed;
if (opaquelen < GSSKRB5TOKHDR_LEN)
goto unwrap_failed;
The first guard makes the subtraction in the second guard
unconditionally safe; offset is derived from a successful
xdrinlinedecode() in the head kvec, so in practice it already
satisfies the bound. The floor mirrors the server-side check added
in commit 5b757c2e57a5 ("SUNRPC: svcauth_gss: enforce krb5 token
minimum length").
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/3691c4b3488d8ca046b9941e5be30c626dbbbb50, https://git.kernel.org/stable/c/401f6a5b338d05bb1069ad814d9f77e3c367854f, https://git.kernel.org/stable/c/81fd7654a8429718adfcb2a7e03496077f547ed0, https://git.kernel.org/stable/c/85fa6b12e8f439739ac36ef2aad925f37c8b976a, https://git.kernel.org/stable/c/87831b92112c81db251d46756d65daa4f91af6a2, https://git.kernel.org/stable/c/89a15a50f84d32d4b99db86f957427fcbe20a99a, https://git.kernel.org/stable/c/d395c30d570ca6168f0297b191709927d1258273, https://git.kernel.org/stable/c/ebcbd2523a8524c3d24e111cdbed8e271d910269, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89541.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89541, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git