Executive brief
A vulnerability in the Linux kernel's SUNRPC implementation can allow a remote attacker to crash the system. SUNRPC is a core component used for network file sharing and remote procedure calls. By sending a specially crafted network packet with a zero-length security checksum, an attacker can trigger a system failure, leading to a denial of service.
Technical details
A null pointer dereference (NPD) exists in the SUNRPC subsystem of the Linux kernel within the svcauth_gss_verify_header() function. When xdr_stream_decode_opaque_auth() encounters a zero-length checksum, it sets the checksum data pointer to NULL. Subsequent access to this pointer in gss_krb5_verify_mic_v2() results in a kernel panic. This can be exploited remotely via the network without authentication. The fix introduces a check to ensure checksum.len is not less than XDR_UNIT. Patches are available in stable kernel branches including 6.6.112, 6.12.53, and 6.17.3.
Affected products
- Linux Linux Kernel 6.3 to 6.17.3
Timeline
- 2025-11-12: advisory: NVD publication date
- 2025-08-11: patched: Original patch authored