Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-89542

SUNRPC: harden gss_krb5_unwrap_v2 against short tokens
Back to all
CVE

CVE-2026-89542

SUNRPC: harden gss_krb5_unwrap_v2 against short tokens

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: harden gsskrb5unwrap_v2 against short tokens

gsskrb5unwrap_v2() reads the EC and RRC header fields at ptr+4 and

ptr+6 before validating that the token is at least GSSKRB5TOKHDRLEN

(16) bytes long, and its rotate_left() helper passes buf->len - base

to xdrbufsubsegment() without verifying that base <= buf->len. When

a caller hands in a sub-16-byte token, or a token whose declared len

leaves base past the end of the buffer, three distinct failures follow:

    gsskrb5unwrap_v2(offset, len, buf)

      ptr = buf->head[0].iov_base + offset

      ec  = (ptr + 4)              / OOB read on short head */

      rrc = (ptr + 6)              / OOB read on short head */

      rotate_left(offset + 16, buf, rrc)

        xdrbufsubsegment(buf, &subbuf,

                           base, buf->len - base)   / u32 wrap when base > len /

        rotateleft(&subbuf, shift)

          shift %= buf->len         / divide-by-zero when base == len /

After decryption, the cleanup arithmetic has the same shape:

    movelen = mint(unsigned int, buf->head[0].iovlen, len);

    movelen -= offset + GSSKRB5TOKHDRLEN + headskip;

    BUGON(offset + GSSKRB5TOKHDR_LEN + headskip + movelen >

                                            buf->head[0].iov_len);

The BUG_ON re-adds the value just subtracted, so it reduces to

min(A, B) > A and is permanently false; it cannot catch the unsigned

underflow of movelen, which then drives a ~UINT_MAX-byte memmove().

Add four defense-in-depth guards inside the unwrap core so it is safe

regardless of what its callers validate:

  • reject tokens with len - offset < GSSKRB5TOKHDRLEN before

    touching ptr+4/ptr+6;

  • bail from rotate_left() when buf->len <= base, covering both the

    underflow and zero-length cases;

  • return early from rotateleft() when buf->len is zero, so the

    shift %= buf->len modulo cannot fault;

  • replace the dead BUG_ON with a live check that returns

    GSSSDEFECTIVE_TOKEN before the movelen subtraction.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/075d7cfc4df8c54cb202ba8b28420370c03ba9b6, https://git.kernel.org/stable/c/299d281c7225ded15b28cb861a98d818d82787fc, https://git.kernel.org/stable/c/6959297aaa9572783d620a226d73c3fb94494888, https://git.kernel.org/stable/c/806584a4b67a7233870c33e5b8f872e76dd02988, https://git.kernel.org/stable/c/84ddbc8d084c0251d534f14f5d1a7da05be56404, https://git.kernel.org/stable/c/a7894e10572d53eb10109b8d07459cc8d3435811, https://git.kernel.org/stable/c/dddcb0f4b7e27fac16a78ea9a1c8ec2e8a241087, https://git.kernel.org/stable/c/f2591660e0eb263c9415bf0d0bb1b111e62df7a4, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89542.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89542, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00514%
EPSS Percentile
0.41943%
Introduced Version
de9c17eb4a912c9028f7b470eb80815144883b26,2.6.35,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
6959297aaa9572783d620a226d73c3fb94494888,5.10.270,5.15.221,6.1.188,6.6.157,6.12.109,6.18.50,7.2.4,6.12.111-1~deb12u1,6.12.111-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading