Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-89550

SUNRPC: svcauth_gss: enforce krb5 token minimum length
Back to all
CVE

CVE-2026-89550

SUNRPC: svcauth_gss: enforce krb5 token minimum length

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: svcauth_gss: enforce krb5 token minimum length

svcauthgssunwrap_priv() validates only an upper bound on the

wire-supplied opaque length before handing the buffer to

gss_unwrap():

    if (len > xdrstreamremaining(xdr))

            goto unwrap_failed;

    offset = xdrstreampos(xdr);

    ...

    majstat = gssunwrap(ctx, offset, offset + len, buf);

The wire value len flows unchanged as the upper bound into the

krb5 unwrap path, so a len in [0, 16] passes this check and is

handed to gss_unwrap(). For a krb5 v2 context that lands in

gsskrb5unwrap_v2(), which reads the 16-byte RFC 4121 token

header fields at ptr+4 and ptr+6 and then calls rotate_left()

before any integrity check. With a sub-header length the header

reads run past the token, and rotateleft()'s shift %= buf->len

path can divide by zero when buf->len has been driven to zero by

the truncated token. A header-only token (len == 16) is equally

invalid: with a non-zero RRC field and the opaque blob ending at

the XDR buffer boundary, rotate_left() builds a zero-length

subbuffer, reaching the same division.

Reject the token at the server entry point before it reaches the

krb5 unwrap core. A valid sealed RFC 4121 token must contain

the 16-byte header plus at least some encrypted payload.

Fix by adding a minimum-length check immediately after the

existing upper-bound check:

    if (len <= GSSKRB5TOKHDRLEN)

            goto unwrap_failed;

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/0ea5b0c7f212c2772d32c2b88287b89a9cdf6edd, https://git.kernel.org/stable/c/2eed1e6a976a44015c3ee78841fe336796e2b21c, https://git.kernel.org/stable/c/a919c5c88769cf8fb3ec071e6078d830bf512489, https://git.kernel.org/stable/c/dd6afc6cab8c5d387d1ed2f069562ef7bdadd651, https://git.kernel.org/stable/c/de942dd8c2c8358bcad04ce44271954c48924423, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89550.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89550, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00457%
EPSS Percentile
0.37667%
Introduced Version
7c9fdcfb1b64c47ed618c103b617af3f86e1239c,2.6.18,6.7.0,6.13.0,6.19.0,0
Fix Available
a919c5c88769cf8fb3ec071e6078d830bf512489,6.6.157,6.12.109,6.18.50,7.2.4,6.12.111-1~deb12u1,6.12.111-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading