KernelScan.io

CRITICAL Introduced in 2.6.18

sunrpc GssToken Deref

CVE-2026-89550

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI6.5MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svcauth_gss: enforce krb5 token minimum length svcauth_gss_unwrap_priv() validates only an upper bound on the wire-supplied opaque length before handing the buffer to gss_unwrap(): if (len > xdr_stream_remaining(xdr)) goto unwrap_failed; offset = xdr_stream_pos(xdr); ... maj_stat = gss_unwrap(ctx, offset, offset + len, buf); The wire value `len` flows unchanged as the upper bound into the krb5 unwrap path, so a len in [0, 16] passes this check and is handed to gss_unwrap(). For a krb5 v2 context that lands in gss_krb5_unwrap_v2(), which reads the 16-byte RFC 4121 token header fields at ptr+4 and ptr+6 and then calls rotate_left() before any integrity check. With a sub-header length the header reads run past the token, and _rotate_left()'s `shift %= buf->len` path can divide by zero when buf->len has been driven to zero by the truncated token. A header-only token (len == 16) is equally invalid: with a non-zero RRC field and the opaque blob ending at the XDR buffer boundary, rotate_left() builds a zero-length subbuffer, reaching the same division. Reject the token at the server entry point before it reaches the krb5 unwrap core. A valid sealed RFC 4121 token must contain the 16-byte header plus at least some encrypted payload. Fix by adding a minimum-length check immediately after the existing upper-bound check: if (len <= GSS_KRB5_TOK_HDR_LEN) goto unwrap_failed;

02

Engine v0.6.0

Risk summary

An authenticated remote attacker can send a crafted RPCSEC_GSS privacy token to an NFS server using Kerberos privacy, causing a divide-by-zero in the kernel and crashing the system. The bug is in the server-side GSS unwrap path and is reachable over the network by any client that has established a valid RPCSEC_GSS context. Valid Kerberos credentials are required to reach the vulnerable code.

Affectednet/sunrpc/auth_gss/svcauth_gss.c (SUNRPC GSS auth)

Vulnerability analysis

The server-side privacy processing for RPCSEC_GSS accepts a wire-supplied token length and only checks an upper bound before passing the buffer to the Kerberos layer. A token with a length at or below the 16-byte header size is allowed through, and the Kerberos v2 path reads header fields and invokes a rotation step before any integrity verification. With a truncated token the rotation step is handed a zero-length subbuffer and performs a divide-by-zero, crashing the kernel. The fix adds a minimum-length check at the server entry so that any token too short to contain the header plus encrypted payload is rejected before reaching the Kerberos layer. The vulnerable path is reached when an NFS server has RPCSEC_GSS privacy enabled and an authenticated client sends a crafted RPC request.

03

BranchIntroducedFixed inPatch commit
6.62.6.186.6.1570ea5b0c7f212
6.182.6.186.18.50de942dd8c2c8
7.22.6.187.2.42eed1e6a976a
mainline2.6.187.3-rc1a919c5c88769
6.122.6.186.12.109dd6afc6cab8c