DEBIAN-CVE-2026-89542
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gsskrb5unwrapv2 against short tokens gsskrb5unwrapv2() reads the EC and RRC header fields at ptr+4 and ptr+6 before validating that the token is at least GSSKRB5TOKHDRLEN (16) bytes long, and its rotateleft() helper passes buf->len - base to xdrbufsubsegment() without verifying that base <= buf->len. When a caller hands in a sub-16-byte token, or a token whose declared len leaves base past the end of the buffer, three distinct failures follow: gsskrb5unwrapv2(offset, len, buf) ptr = buf->head[0].iovbase + offset ec = (ptr + 4) / OOB read on short head / rrc = (ptr + 6) / OOB read on short head / rotateleft(offset + 16, buf, rrc) xdrbufsubsegment(buf, &subbuf, base, buf->len - base) / u32 wrap when base > len / rotateleft(&subbuf, shift) shift %= buf->len / divide-by-zero when base == len / After decryption, the cleanup arithmetic has the same shape: movelen = mint(unsigned int, buf->head[0].iovlen, len); movelen -= offset + GSSKRB5TOKHDRLEN + headskip; BUGON(offset + GSSKRB5TOKHDRLEN + headskip + movelen > buf->head[0].iovlen); The BUGON re-adds the value just subtracted, so it reduces to min(A, B) > A and is permanently false; it cannot catch the unsigned underflow of movelen, which then drives a ~UINTMAX-byte memmove(). Add four defense-in-depth guards inside the unwrap core so it is safe regardless of what its callers validate: - reject tokens with len - offset < GSSKRB5TOKHDRLEN before touching ptr+4/ptr+6; - bail from rotateleft() when buf->len <= base, covering both the underflow and zero-length cases; - return early from rotateleft() when buf->len is zero, so the shift %= buf->len modulo cannot fault; - replace the dead BUGON with a live check that returns GSSSDEFECTIVE_TOKEN before the movelen subtraction.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-89542