Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-89541

SUNRPC: harden gss_unwrap_resp_priv length checks
Back to all
CVE

CVE-2026-89541

SUNRPC: harden gss_unwrap_resp_priv length checks

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: harden gssunwrapresp_priv length checks

gssunwrapresppriv() validates the RPCSECGSS opaque length with

    offset = (u8 )(p) - (u8 )head->iov_base;

    if (offset + opaquelen > rcvbuf->len)

            goto unwrap_failed;

    majstat = gssunwrap(ctx->gcgssctx, offset,

                          offset + opaquelen, rcvbuf);

Both operands are u32 and the sum is computed in u32. A reply with

opaquelen near 0xffffffff makes offset + opaquelen wrap to a small

value that is below rcv_buf->len, so the bound check passes and

gss_unwrap() is called with end < begin. The check also lacks a

lower bound, so any opaquelen in [0, GSSKRB5TOKHDR_LEN) is

accepted and forwarded to gsskrb5unwrap_v2(), whose pre-decrypt

header reads at ptr+4 and ptr+6 then run past the token.

A krb5p NFS server returning a crafted RPCSEC_GSS reply can drive

the client into out-of-bounds reads in gsskrb5unwrap_v2() and the

rotate_left() loop that follows.

Fix by replacing the single combined check with three guards that

are safe in u32 arithmetic and that enforce the RFC 4121 minimum

outer token length:

    if (offset > rcv_buf->len)

            goto unwrap_failed;

    if (opaquelen > rcvbuf->len - offset)

            goto unwrap_failed;

    if (opaquelen < GSSKRB5TOKHDR_LEN)

            goto unwrap_failed;

The first guard makes the subtraction in the second guard

unconditionally safe; offset is derived from a successful

xdrinlinedecode() in the head kvec, so in practice it already

satisfies the bound. The floor mirrors the server-side check added

in commit 5b757c2e57a5 ("SUNRPC: svcauth_gss: enforce krb5 token

minimum length").

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/3691c4b3488d8ca046b9941e5be30c626dbbbb50, https://git.kernel.org/stable/c/401f6a5b338d05bb1069ad814d9f77e3c367854f, https://git.kernel.org/stable/c/81fd7654a8429718adfcb2a7e03496077f547ed0, https://git.kernel.org/stable/c/85fa6b12e8f439739ac36ef2aad925f37c8b976a, https://git.kernel.org/stable/c/87831b92112c81db251d46756d65daa4f91af6a2, https://git.kernel.org/stable/c/89a15a50f84d32d4b99db86f957427fcbe20a99a, https://git.kernel.org/stable/c/d395c30d570ca6168f0297b191709927d1258273, https://git.kernel.org/stable/c/ebcbd2523a8524c3d24e111cdbed8e271d910269, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89541.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89541, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00514%
EPSS Percentile
0.41946%
Introduced Version
2d2da60c63b67174add32f06e8d54c3a0c5cd9cf,2.6.15,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
87831b92112c81db251d46756d65daa4f91af6a2,5.10.270,5.15.221,6.1.188,6.6.157,6.12.109,6.18.50,7.2.4,6.12.111-1~deb12u1,6.12.111-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading