DEBIAN-CVE-2026-89537
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Reject short RFC 4121 MIC tokens in gsskrb5verifymicv2 gsskrb5verifymicv2() reads the token ID at ptr[0..1], the flags byte at ptr[2], and padding at ptr[3..7], then passes ptr + GSSKRB5TOKHDRLEN and cksumlen to gsskrb5micbuildsg(). None of these accesses check readtoken->len first. The minimum safe token size is GSSKRB5TOKHDRLEN (16) plus ctx->krb5e->cksumlen (12-24, depending on the enctype). All callers accept shorter tokens from the wire: - gssunwraprespinteg() enforces only an upper bound (offset + len <= rcvbuf->len) before allocating mic.data = kmalloc(len) and passing it to gssverifymic(). A malicious NFS server can therefore supply a short checksum opaque, producing a small slab allocation that the Kerberos MIC verifier reads past. - gssvalidate() enforces only len <= RPCMAXAUTHSIZE (400) before passing the wire-supplied length to gssvalidateseqnomic(), which constructs a mic xdrnetobj and calls gssverifymic(). - svcauthgssverifyheader() enforces only checksum.len >= XDRUNIT (4 bytes) before dispatching to gssverifymic(). - svcauthgssunwrapinteg() checks only that the checksum fits in gsd->gsdscratch. Add a length guard at the top of gsskrb5verifymicv2(), before any ptr[] access or scatterlist construction. Well-formed MIC tokens from gsskrb5getmicv2() already have exactly GSSKRB5TOKHDRLEN + cksumlen bytes, so valid traffic is unaffected.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-89537