From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 61EB73DD86F for ; Fri, 11 Sep 2026 19:54:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156510; cv=none; b=q7vQx2oKF0sM+wFMbgi3sOQXdIue6CMxi1fRNK4ZRscFgVHLL9u7/AusfViYzLC6OtIT/eurNb958LIAzFQESEjFCmeaZ4n1myF0SK97VkOsmMa1OrGcAZLICCP5f9b/s1GKzrzwZN78K5EE6W9Zp/bMCNjBOqtBvWcbqN2rDvY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156510; c=relaxed/simple; bh=q5cD6o4gQ7LsAejzqFSGDNFXQl49IyH3hEfbeNVzgHk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=ijjH4TOum/9zI6EDw/8FL35F7C/fgkd8jZuB34OG3VjVbRqtmdquPwbDShn/NswQcq9E+cy9KG+bNpmZp5gNchWwsDLXw/AlZuf1XirFDIoutdHwn396L2Pf2JyOWtRkp0B8OZo5jlPrT/QII5b7zPRS8GtOHsMqReCuYoKYKrY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=hScQZNfn; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="hScQZNfn" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 188621F00898; Fri, 11 Sep 2026 19:54:56 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156497; bh=8urWhucEKFNeyEY8ZT+sfyKjaS0tLBh3hrWBtMKy32M=; h=From:To:Cc:Subject:Date:Reply-To; b=hScQZNfnqKDGH6a+Fhy7x+Ju66uK4x5B2Hw08FKilg06rr6eElZrueSY/4Aw6FEav aYUMAG1nBFcKS1jfBg5pthBh0Yg0UR4n6T8ovqeJpAbyNJ9uFA9WjU80yvt6cCyxu9 Ry1Tlt0GpkuP7GodjeqM2FNR+XmaeNfjNo8y3G+g= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89537: SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2 Date: Fri, 11 Sep 2026 21:43:46 +0200 Message-ID: <2026091118-CVE-2026-89537-414e@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3241; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=Toc9esXIdUfJ/SPCcv2XHZp7tcQ3Kic7VIlt6wcKADo=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIuPkHmXY+5XuX76Ex37zs5NblrhHTc6+6xzstiT8e YPN/nyLjlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZjIAQWGBdud3rrdvNnLIpGr xxOtcVO52Kv+AMOCzlarpWdVN3i0yhbd8d72LCxQouUtAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2 gss_krb5_verify_mic_v2() reads the token ID at ptr[0..1], the flags byte at ptr[2], and padding at ptr[3..7], then passes ptr + GSS_KRB5_TOK_HDR_LEN and cksum_len to gss_krb5_mic_build_sg(). None of these accesses check read_token->len first. The minimum safe token size is GSS_KRB5_TOK_HDR_LEN (16) plus ctx->krb5e->cksum_len (12-24, depending on the enctype). All callers accept shorter tokens from the wire: - gss_unwrap_resp_integ() enforces only an upper bound (offset + len <= rcv_buf->len) before allocating mic.data = kmalloc(len) and passing it to gss_verify_mic(). A malicious NFS server can therefore supply a short checksum opaque, producing a small slab allocation that the Kerberos MIC verifier reads past. - gss_validate() enforces only len <= RPC_MAX_AUTH_SIZE (400) before passing the wire-supplied length to gss_validate_seqno_mic(), which constructs a mic xdr_netobj and calls gss_verify_mic(). - svcauth_gss_verify_header() enforces only checksum.len >= XDR_UNIT (4 bytes) before dispatching to gss_verify_mic(). - svcauth_gss_unwrap_integ() checks only that the checksum fits in gsd->gsd_scratch. Add a length guard at the top of gss_krb5_verify_mic_v2(), before any ptr[] access or scatterlist construction. Well-formed MIC tokens from gss_krb5_get_mic_v2() already have exactly GSS_KRB5_TOK_HDR_LEN + cksum_len bytes, so valid traffic is unaffected. The Linux kernel CVE team has assigned CVE-2026-89537 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.35 with commit de9c17eb4a912c9028f7b470eb80815144883b26 and fixed in 7.2.4 with commit 7a946b2e7207f968902f2147ab9b30726f82f7ab Issue introduced in 2.6.35 with commit de9c17eb4a912c9028f7b470eb80815144883b26 and fixed in 7.3-rc1 with commit b94f6719dcd9f7a609bc5f459f85795900e77d25 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89537 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/sunrpc/auth_gss/gss_krb5_unseal.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/7a946b2e7207f968902f2147ab9b30726f82f7ab https://git.kernel.org/stable/c/b94f6719dcd9f7a609bc5f459f85795900e77d25