KernelScan.io

CRITICAL Introduced in 2.6.35

sunrpc UnwrapV2 OOB

CVE-2026-89542

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI9.8CRITICAL

01

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_krb5_unwrap_v2 against short tokens gss_krb5_unwrap_v2() reads the EC and RRC header fields at ptr+4 and ptr+6 before validating that the token is at least GSS_KRB5_TOK_HDR_LEN (16) bytes long, and its rotate_left() helper passes buf->len - base to xdr_buf_subsegment() without verifying that base <= buf->len. When a caller hands in a sub-16-byte token, or a token whose declared len leaves base past the end of the buffer, three distinct failures follow: gss_krb5_unwrap_v2(offset, len, buf) ptr = buf->head[0].iov_base + offset ec = *(ptr + 4) /* OOB read on short head */ rrc = *(ptr + 6) /* OOB read on short head */ rotate_left(offset + 16, buf, rrc) xdr_buf_subsegment(buf, &subbuf, base, buf->len - base) /* u32 wrap when base > len */ _rotate_left(&subbuf, shift) shift %= buf->len /* divide-by-zero when base == len */ After decryption, the cleanup arithmetic has the same shape: movelen = min_t(unsigned int, buf->head[0].iov_len, len); movelen -= offset + GSS_KRB5_TOK_HDR_LEN + headskip; BUG_ON(offset + GSS_KRB5_TOK_HDR_LEN + headskip + movelen > buf->head[0].iov_len); The BUG_ON re-adds the value just subtracted, so it reduces to min(A, B) > A and is permanently false; it cannot catch the unsigned underflow of movelen, which then drives a ~UINT_MAX-byte memmove(). Add four defense-in-depth guards inside the unwrap core so it is safe regardless of what its callers validate: - reject tokens with len - offset < GSS_KRB5_TOK_HDR_LEN before touching ptr+4/ptr+6; - bail from rotate_left() when buf->len <= base, covering both the underflow and zero-length cases; - return early from _rotate_left() when buf->len is zero, so the shift %= buf->len modulo cannot fault; - replace the dead BUG_ON with a live check that returns GSS_S_DEFECTIVE_TOKEN before the movelen subtraction.

02

Engine v0.6.0

Risk summary

A remote attacker who can send RPC traffic to a device using NFS with Kerberos (RPCSEC_GSS) can trigger out-of-bounds reads and a massive out-of-bounds write by sending a crafted short GSS token. This can lead to kernel memory disclosure, memory corruption, and kernel panic, potentially enabling remote code execution with no authentication required. Any system exposing NFS services over the network is at risk.

Affectednet/sunrpc/auth_gss/gss_krb5_wrap.c (sunrpc auth_gss)

Vulnerability analysis

The Kerberos v2 token unwrapping routine in the SUNRPC GSS layer reads header fields from an incoming token before checking that the token is long enough to contain them, and performs buffer-length arithmetic that can underflow when the token's declared length is inconsistent with the actual buffer. A short or malformed token causes out-of-bounds reads of header fields, an integer wrap in a sub-buffer calculation that can trigger a divide-by-zero, and an unsigned underflow in a cleanup length that drives a memmove of nearly the maximum possible size — corrupting kernel memory and crashing the system. The fix adds early length validation before any header access, guards the rotation helpers against zero-length and underflowing buffer sizes, and replaces a dead assertion with a live bounds check that rejects defective tokens before the dangerous subtraction. The vulnerable path is reached when any NFS client or server processes an incoming RPCSEC_GSS Kerberos token, so a remote peer who can send RPC traffic to the target — with no prior authentication — can trigger it.

03

BranchIntroducedFixed inPatch commit
5.102.6.355.10.270299d281c7225
5.152.6.355.15.22184ddbc8d084c
6.122.6.356.12.109dddcb0f4b7e2
6.62.6.356.6.157f2591660e0eb
6.12.6.356.1.188075d7cfc4df8
mainline2.6.357.3-rc16959297aaa95
6.182.6.356.18.50806584a4b67a
7.22.6.357.2.4a7894e10572d