{"id":"CVE-2026-89542","title":"SUNRPC: harden gss_krb5_unwrap_v2 against short tokens","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: harden gss_krb5_unwrap_v2 against short tokens\n\ngss_krb5_unwrap_v2() reads the EC and RRC header fields at ptr+4 and\nptr+6 before validating that the token is a…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","vendor":"Linux","product":"Linux","affected":["Linux >= de9c17eb4a912c9028f7b470eb80815144883b26 < 299d281c7225ded15b28cb861a98d818d82787fc","Linux >= de9c17eb4a912c9028f7b470eb80815144883b26 < 84ddbc8d084c0251d534f14f5d1a7da05be56404","Linux >= de9c17eb4a912c9028f7b470eb80815144883b26 < 075d7cfc4df8c54cb202ba8b28420370c03ba9b6","Linux >= de9c17eb4a912c9028f7b470eb80815144883b26 < f2591660e0eb263c9415bf0d0bb1b111e62df7a4","Linux >= de9c17eb4a912c9028f7b470eb80815144883b26 < dddcb0f4b7e27fac16a78ea9a1c8ec2e8a241087","Linux >= de9c17eb4a912c9028f7b470eb80815144883b26 < 806584a4b67a7233870c33e5b8f872e76dd02988","Linux >= de9c17eb4a912c9028f7b470eb80815144883b26 < a7894e10572d53eb10109b8d07459cc8d3435811","Linux >= de9c17eb4a912c9028f7b470eb80815144883b26 < 6959297aaa9572783d620a226d73c3fb94494888","Linux 2.6.35"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T12:00:49.355Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-89542","references":[{"url":"https://git.kernel.org/stable/c/299d281c7225ded15b28cb861a98d818d82787fc"},{"url":"https://git.kernel.org/stable/c/84ddbc8d084c0251d534f14f5d1a7da05be56404"},{"url":"https://git.kernel.org/stable/c/075d7cfc4df8c54cb202ba8b28420370c03ba9b6"},{"url":"https://git.kernel.org/stable/c/f2591660e0eb263c9415bf0d0bb1b111e62df7a4"},{"url":"https://git.kernel.org/stable/c/dddcb0f4b7e27fac16a78ea9a1c8ec2e8a241087"},{"url":"https://git.kernel.org/stable/c/806584a4b67a7233870c33e5b8f872e76dd02988"},{"url":"https://git.kernel.org/stable/c/a7894e10572d53eb10109b8d07459cc8d3435811"},{"url":"https://git.kernel.org/stable/c/6959297aaa9572783d620a226d73c3fb94494888"}],"tags":["cve.org"],"epss":0.00521,"epssPercentile":0.43235,"ingestedAt":"2026-09-14T15:23:07.452Z","slug":"CVE-2026-89542","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: harden gss_krb5_unwrap_v2 against short tokens\n\ngss_krb5_unwrap_v2() reads the EC and RRC header fields at ptr+4 and\nptr+6 before validating that the token is at least GSS_KRB5_TOK_HDR_LEN\n(16) bytes long, and its rotate_left() helper passes buf->len - base\nto xdr_buf_subsegment() without verifying that base <= buf->len. When\na caller hands in a sub-16-byte token, or a token whose declared len\nleaves base past the end of the buffer, three distinct failures follow:\n\n    gss_krb5_unwrap_v2(offset, len, buf)\n      ptr = buf->head[0].iov_base + offset\n      ec  = *(ptr + 4)              /* OOB read on short head */\n      rrc = *(ptr + 6)              /* OOB read on short head */\n      rotate_left(offset + 16, buf, rrc)\n        xdr_buf_subsegment(buf, &subbuf,\n                           base, buf->len - base)   /* u32 wrap when base > len */\n        _rotate_left(&subbuf, shift)\n          shift %= buf->len         /* divide-by-zero when base == len */\n\nAfter decryption, the cleanup arithmetic has the same shape:\n\n    movelen = min_t(unsigned int, buf->head[0].iov_len, len);\n    movelen -= offset + GSS_KRB5_TOK_HDR_LEN + headskip;\n    BUG_ON(offset + GSS_KRB5_TOK_HDR_LEN + headskip + movelen >\n                                            buf->head[0].iov_len);\n\nThe BUG_ON re-adds the value just subtracted, so it reduces to\nmin(A, B) > A and is permanently false; it cannot catch the unsigned\nunderflow of movelen, which then drives a ~UINT_MAX-byte memmove().\n\nAdd four defense-in-depth guards inside the unwrap core so it is safe\nregardless of what its callers validate:\n\n  - reject tokens with len - offset < GSS_KRB5_TOK_HDR_LEN before\n    touching ptr+4/ptr+6;\n  - bail from rotate_left() when buf->len <= base, covering both the\n    underflow and zero-length cases;\n  - return early from _rotate_left() when buf->len is zero, so the\n    shift %= buf->len modulo cannot fault;\n  - replace the dead BUG_ON with a live check that returns\n    GSS_S_DEFECTIVE_TOKEN before the movelen subtraction.\n\n## Affected\n\n- `Linux >= de9c17eb4a912c9028f7b470eb80815144883b26 < 299d281c7225ded15b28cb861a98d818d82787fc`\n- `Linux >= de9c17eb4a912c9028f7b470eb80815144883b26 < 84ddbc8d084c0251d534f14f5d1a7da05be56404`\n- `Linux >= de9c17eb4a912c9028f7b470eb80815144883b26 < 075d7cfc4df8c54cb202ba8b28420370c03ba9b6`\n- `Linux >= de9c17eb4a912c9028f7b470eb80815144883b26 < f2591660e0eb263c9415bf0d0bb1b111e62df7a4`\n- `Linux >= de9c17eb4a912c9028f7b470eb80815144883b26 < dddcb0f4b7e27fac16a78ea9a1c8ec2e8a241087`\n- `Linux >= de9c17eb4a912c9028f7b470eb80815144883b26 < 806584a4b67a7233870c33e5b8f872e76dd02988`\n- `Linux >= de9c17eb4a912c9028f7b470eb80815144883b26 < a7894e10572d53eb10109b8d07459cc8d3435811`\n- `Linux >= de9c17eb4a912c9028f7b470eb80815144883b26 < 6959297aaa9572783d620a226d73c3fb94494888`\n- `Linux 2.6.35`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":197947,"id":"CVE-2026-89542","ts":1789384321088,"field":"cvss","old":"7.7","new":"9.8"},{"seq":197946,"id":"CVE-2026-89542","ts":1789384321088,"field":"severity","old":"high","new":"critical"},{"seq":183756,"id":"CVE-2026-89542","ts":1789356677256,"field":"cvss","old":"9.8","new":"7.7"},{"seq":183755,"id":"CVE-2026-89542","ts":1789356677256,"field":"severity","old":"critical","new":"high"},{"seq":153342,"id":"CVE-2026-89542","ts":1789285350121,"field":"cvss","old":null,"new":"9.8"},{"seq":153341,"id":"CVE-2026-89542","ts":1789285350121,"field":"severity","old":"none","new":"critical"},{"seq":147574,"id":"CVE-2026-89542","ts":1789270211442,"field":"cvss","old":null,"new":"7.7"},{"seq":147573,"id":"CVE-2026-89542","ts":1789270211442,"field":"severity","old":"none","new":"high"},{"seq":109326,"id":"CVE-2026-89542","ts":1789183731436,"field":"cvss","old":null,"new":"7.7"},{"seq":109325,"id":"CVE-2026-89542","ts":1789183731436,"field":"severity","old":"none","new":"high"}]}