Junglewise Threat Intelligence

CVE-2026-89538: Linux kernel SUNRPC Kerberos v2 buffer validation bypass

CVE-2026-89538 · Severity: critical · CVSS 9.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's SUNRPC (Sun RPC) module allows remote attackers with a valid Kerberos authentication context to send malformed Kerberos v2 tokens that bypass buffer validation. An attacker could exploit this to cause kernel memory corruption, system crashes, or potentially achieve code execution on systems using Kerberos-based network authentication.

Technical details

The vulnerability exists in the gss_krb5_unwrap_v2() function, which processes Kerberos v2 wrap tokens but fails to properly validate the authenticated "extra count" (ec) field in the token header before trimming the buffer. Although the ec field is encrypted and authenticated via post-decrypt memcmp(), a legitimate peer can construct a token with an oversized ec value that exceeds the plaintext length, violating RFC 4121. When xdr_buf_trim() is called with such an oversized value, it leaves the xdr_buf in a semantically invalid state. The fix adds validation to reject tokens where ec exceeds the remaining wrapped segment (buf->len - offset) before calling xdr_buf_trim(), returning a GSS_S_DEFECTIVE_TOKEN error and maintaining buffer consistency. Attack requires network access to a system using Kerberos authentication and a valid GSS context.

Affected products

  • Linux Linux kernel <UNKNOWN>

Timeline

  • 2026-09-11: disclosed

Related threats