Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-89542

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_krb5_unwrap_v2 against short tokens gss_krb5_unwrap_v2() reads the EC and RRC header fields at ptr+4 and ptr+6 ...
Back to all
CVE

DEBIAN-CVE-2026-89542

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_krb5_unwrap_v2 against short tokens gss_krb5_unwrap_v2() reads the EC and RRC header fields at ptr+4 and ptr+6 ...

In the Linux kernel, the following vulnerability has been resolved:  SUNRPC: harden gsskrb5unwrapv2 against short tokens  gsskrb5unwrapv2() reads the EC and RRC header fields at ptr+4 and ptr+6 before validating that the token is at least GSSKRB5TOKHDRLEN (16) bytes long, and its rotateleft() helper passes buf->len - base to xdrbufsubsegment() without verifying that base <= buf->len. When a caller hands in a sub-16-byte token, or a token whose declared len leaves base past the end of the buffer, three distinct failures follow:      gsskrb5unwrapv2(offset, len, buf)       ptr = buf->head[0].iovbase + offset       ec  = (ptr + 4)              / OOB read on short head /       rrc = (ptr + 6)              / OOB read on short head /       rotateleft(offset + 16, buf, rrc)         xdrbufsubsegment(buf, &subbuf,                            base, buf->len - base)   / u32 wrap when base > len /         rotateleft(&subbuf, shift)           shift %= buf->len         / divide-by-zero when base == len /  After decryption, the cleanup arithmetic has the same shape:      movelen = mint(unsigned int, buf->head[0].iovlen, len);     movelen -= offset + GSSKRB5TOKHDRLEN + headskip;     BUGON(offset + GSSKRB5TOKHDRLEN + headskip + movelen >                                             buf->head[0].iovlen);  The BUGON re-adds the value just subtracted, so it reduces to min(A, B) > A and is permanently false; it cannot catch the unsigned underflow of movelen, which then drives a ~UINTMAX-byte memmove().  Add four defense-in-depth guards inside the unwrap core so it is safe regardless of what its callers validate:    - reject tokens with len - offset < GSSKRB5TOKHDRLEN before     touching ptr+4/ptr+6;   - bail from rotateleft() when buf->len <= base, covering both the     underflow and zero-length cases;   - return early from rotateleft() when buf->len is zero, so the     shift %= buf->len modulo cannot fault;   - replace the dead BUGON with a live check that returns     GSSSDEFECTIVE_TOKEN before the movelen subtraction.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-89542

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
6.12.111-1,7.2.6-1,6.12.111-1~deb12u1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading