DEBIAN-CVE-2026-89551
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: xdrbuftrim: clamp buf->len to avoid underflow xdrbuftrim() trims len bytes from the tail of an xdrbuf by walking the tail, pages, and head iovecs. Each per-section step uses mint() so it never removes more bytes than that section holds, but the final accounting at the fixlen label subtracts the total bytes actually consumed from buf->len without any clamp: fixlen: buf->len -= (len - trim); When the caller has set buf->len to a value smaller than the sum of the iovlens, (len - trim) can exceed buf->len and the unsigned subtraction wraps to near UINTMAX. gsskrb5unwrapv2() reaches xdrbuftrim() in exactly that state: buf->head[0].iovlen -= GSSKRB5TOKHDRLEN + headskip; buf->len = len - (GSSKRB5TOKHDRLEN + headskip); xdrbuftrim(buf, ec + GSSKRB5TOKHDRLEN + tailskip); buf->len is a small wire-derived value while the iovlens are at page scale, so the per-section loops legitimately consume far more bytes than buf->len records. The wrapped buf->len then propagates as the authoritative stream bound into every downstream XDR decoder. Fix by clamping the decrement so buf->len bottoms out at zero: buf->len -= mint(unsigned int, buf->len, len - trim); On the normal path where the iov_lens sum to buf->len, (len - trim) is always <= buf->len and the result is identical to before. No callers change behavior outside the underflow case.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-89551