Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-89541

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_unwrap_resp_priv length checks gss_unwrap_resp_priv() validates the RPCSEC_GSS opaque length with offset =...
Back to all
CVE

DEBIAN-CVE-2026-89541

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_unwrap_resp_priv length checks gss_unwrap_resp_priv() validates the RPCSEC_GSS opaque length with offset =...

In the Linux kernel, the following vulnerability has been resolved:  SUNRPC: harden gssunwrapresppriv length checks  gssunwrapresppriv() validates the RPCSECGSS opaque length with      offset = (u8 )(p) - (u8 )head->iovbase;     if (offset + opaquelen > rcvbuf->len)             goto unwrapfailed;     majstat = gssunwrap(ctx->gcgssctx, offset,                           offset + opaquelen, rcvbuf);  Both operands are u32 and the sum is computed in u32. A reply with opaquelen near 0xffffffff makes offset + opaquelen wrap to a small value that is below rcvbuf->len, so the bound check passes and gssunwrap() is called with end < begin. The check also lacks a lower bound, so any opaquelen in [0, GSSKRB5TOKHDRLEN) is accepted and forwarded to gsskrb5unwrapv2(), whose pre-decrypt header reads at ptr+4 and ptr+6 then run past the token.  A krb5p NFS server returning a crafted RPCSECGSS reply can drive the client into out-of-bounds reads in gsskrb5unwrapv2() and the rotateleft() loop that follows.  Fix by replacing the single combined check with three guards that are safe in u32 arithmetic and that enforce the RFC 4121 minimum outer token length:      if (offset > rcvbuf->len)             goto unwrapfailed;     if (opaquelen > rcvbuf->len - offset)             goto unwrapfailed;     if (opaquelen < GSSKRB5TOKHDRLEN)             goto unwrapfailed;  The first guard makes the subtraction in the second guard unconditionally safe; offset is derived from a successful xdrinlinedecode() in the head kvec, so in practice it already satisfies the bound. The floor mirrors the server-side check added in commit 5b757c2e57a5 ("SUNRPC: svcauthgss: enforce krb5 token minimum length").

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-89541

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
6.12.111-1,7.2.6-1,6.12.111-1~deb12u1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading