* CVE-2026-89541: SUNRPC: harden gss_unwrap_resp_priv length checks
@ 2026-09-11 19:43 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:43 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: harden gss_unwrap_resp_priv length checks
gss_unwrap_resp_priv() validates the RPCSEC_GSS opaque length with
offset = (u8 *)(p) - (u8 *)head->iov_base;
if (offset + opaque_len > rcv_buf->len)
goto unwrap_failed;
maj_stat = gss_unwrap(ctx->gc_gss_ctx, offset,
offset + opaque_len, rcv_buf);
Both operands are u32 and the sum is computed in u32. A reply with
opaque_len near 0xffffffff makes offset + opaque_len wrap to a small
value that is below rcv_buf->len, so the bound check passes and
gss_unwrap() is called with end < begin. The check also lacks a
lower bound, so any opaque_len in [0, GSS_KRB5_TOK_HDR_LEN) is
accepted and forwarded to gss_krb5_unwrap_v2(), whose pre-decrypt
header reads at ptr+4 and ptr+6 then run past the token.
A krb5p NFS server returning a crafted RPCSEC_GSS reply can drive
the client into out-of-bounds reads in gss_krb5_unwrap_v2() and the
rotate_left() loop that follows.
Fix by replacing the single combined check with three guards that
are safe in u32 arithmetic and that enforce the RFC 4121 minimum
outer token length:
if (offset > rcv_buf->len)
goto unwrap_failed;
if (opaque_len > rcv_buf->len - offset)
goto unwrap_failed;
if (opaque_len < GSS_KRB5_TOK_HDR_LEN)
goto unwrap_failed;
The first guard makes the subtraction in the second guard
unconditionally safe; offset is derived from a successful
xdr_inline_decode() in the head kvec, so in practice it already
satisfies the bound. The floor mirrors the server-side check added
in commit 5b757c2e57a5 ("SUNRPC: svcauth_gss: enforce krb5 token
minimum length").
The Linux kernel CVE team has assigned CVE-2026-89541 to this issue.
Affected and fixed versions
===========================
Issue introduced in 2.6.15 with commit 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf and fixed in 6.12.109 with commit 89a15a50f84d32d4b99db86f957427fcbe20a99a
Issue introduced in 2.6.15 with commit 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf and fixed in 6.18.50 with commit ebcbd2523a8524c3d24e111cdbed8e271d910269
Issue introduced in 2.6.15 with commit 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf and fixed in 7.2.4 with commit d395c30d570ca6168f0297b191709927d1258273
Issue introduced in 2.6.15 with commit 2d2da60c63b67174add32f06e8d54c3a0c5cd9cf and fixed in 7.3-rc1 with commit 87831b92112c81db251d46756d65daa4f91af6a2
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-89541
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
net/sunrpc/auth_gss/auth_gss.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/89a15a50f84d32d4b99db86f957427fcbe20a99a
https://git.kernel.org/stable/c/ebcbd2523a8524c3d24e111cdbed8e271d910269
https://git.kernel.org/stable/c/d395c30d570ca6168f0297b191709927d1258273
https://git.kernel.org/stable/c/87831b92112c81db251d46756d65daa4f91af6a2
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-11 19:55 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:43 CVE-2026-89541: SUNRPC: harden gss_unwrap_resp_priv length checks Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.