KernelScan.io

CRITICAL Introduced in 2.6.35

sunrpc MicToken OOB

CVE-2026-89537

CVSS 9.1 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

KernelScan AI5.7MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2 gss_krb5_verify_mic_v2() reads the token ID at ptr[0..1], the flags byte at ptr[2], and padding at ptr[3..7], then passes ptr + GSS_KRB5_TOK_HDR_LEN and cksum_len to gss_krb5_mic_build_sg(). None of these accesses check read_token->len first. The minimum safe token size is GSS_KRB5_TOK_HDR_LEN (16) plus ctx->krb5e->cksum_len (12-24, depending on the enctype). All callers accept shorter tokens from the wire: - gss_unwrap_resp_integ() enforces only an upper bound (offset + len <= rcv_buf->len) before allocating mic.data = kmalloc(len) and passing it to gss_verify_mic(). A malicious NFS server can therefore supply a short checksum opaque, producing a small slab allocation that the Kerberos MIC verifier reads past. - gss_validate() enforces only len <= RPC_MAX_AUTH_SIZE (400) before passing the wire-supplied length to gss_validate_seqno_mic(), which constructs a mic xdr_netobj and calls gss_verify_mic(). - svcauth_gss_verify_header() enforces only checksum.len >= XDR_UNIT (4 bytes) before dispatching to gss_verify_mic(). - svcauth_gss_unwrap_integ() checks only that the checksum fits in gsd->gsd_scratch. Add a length guard at the top of gss_krb5_verify_mic_v2(), before any ptr[] access or scatterlist construction. Well-formed MIC tokens from gss_krb5_get_mic_v2() already have exactly GSS_KRB5_TOK_HDR_LEN + cksum_len bytes, so valid traffic is unaffected.

02

Engine v0.6.0

Risk summary

A remote attacker acting as a malicious NFS server or client can send a truncated Kerberos MIC token during RPCSEC_GSS authentication, causing the kernel to read past the end of a small slab allocation. This can leak adjacent slab memory contents or, in some configurations, crash the kernel. Any system using NFS with Kerberos authentication (sec=krb5) is potentially affected on both the client and server sides.

Affectednet/sunrpc/auth_gss/gss_krb5_unseal.c (SUNRPC GSS Kerberos)

Vulnerability analysis

The Kerberos MIC token verifier in the kernel's SUNRPC GSS layer reads fixed-size header fields and constructs a cryptographic scatterlist from the token buffer without first checking that the token is long enough to contain them. Callers on both the NFS client and server sides enforce only loose upper bounds or minimal lower bounds on the token length, so a malicious NFS peer can supply a short token that produces a small slab allocation which the verifier then reads past, accessing memory from adjacent slab objects. The fix adds a length check at the very start of the verification function that rejects any token shorter than the minimum safe size before any pointer dereference or scatterlist construction. The attack is reachable over the network by any NFS peer using Kerberos authentication — a malicious server targeting a client, or a malicious client targeting a server — with no special privileges beyond the ability to send NFS RPC traffic.

03

BranchIntroducedFixed inPatch commit
7.22.6.357.2.47a946b2e7207
mainline2.6.357.3-rc1b94f6719dcd9