Executive brief
A vulnerability in the Linux kernel's network file sharing component could allow a local user to crash the system. The issue occurs when the system processes specific security tokens used for authentication. An exploit would result in a denial-of-service, potentially disrupting business operations and data availability.
Technical details
A NULL pointer dereference exists in the SUNRPC svcauth_gss implementation within the gss_read_proxy_verf function. When a zero-length GSS token is processed, the code fails to validate the presence of memory pages before attempting a memory copy operation. Specifically, the kernel unconditionally evaluates page_address(in_token->pages[0]), which is NULL when the token length is zero. A local attacker can trigger this condition to cause a kernel panic (Denial of Service). The issue has been addressed by adding a check to ensure the copy operation only proceeds if the length is greater than zero.
Affected products
- Linux Linux Kernel 5866efa8cbfb to 1c8bb965e9b0559ff0f5690615a527c30f651dd8
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6 and later
Timeline
- 2025-01-14: disclosed
- 2026-01-14: advisory
- 2026-01-02: patched: Initial patch committed to stable tree
References
- https://git.kernel.org/stable/c/1c8bb965e9b0559ff0f5690615a527c30f651dd8
- https://git.kernel.org/stable/c/4dedb6a11243a5c9eb9dbb97bca3c98bd725e83d
- https://git.kernel.org/stable/c/7452d53f293379e2c38cfa8ad0694aa46fc4788b
- https://git.kernel.org/stable/c/a2c6f25ab98b423f99ccd94874d655b8bcb01a19
- https://git.kernel.org/stable/c/a8f1e445ce3545c90d69c9e8ff8f7821825fe810
- https://git.kernel.org/stable/c/d4b69a6186b215d2dc1ebcab965ed88e8d41768d
- https://git.kernel.org/stable/c/f9e53f69ac3bc4ef568b08d3542edac02e83fefd