« Volver al listado

CVE-2026-89544

Estado: RecibidaAlta (7.5)—

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: fix gssx_dec_option_array error path bugs

Four coupled defects in the gssx XDR option-array decoder make the error paths unsafe: a NULL deref in the caller, a refcount leak on the decoded group_info, and a latent use-after-free that the leak fix would otherwise expose.

gssx_dec_option_array() sets oa->count = 1 before allocating oa->data. If that allocation fails, -ENOMEM is returned with oa->count == 1 and oa->data == NULL. All other error paths jump to free_oa: which frees oa->data and NULLs it but also leaves oa->count == 1. The caller trusts the count:

Leer descripción completaMostrar menos

Independently, free_creds: releases the partially decoded svc_cred with a bare kfree(creds). gssx_dec_linux_creds() installs a groups_alloc() result into creds->cr_group_info; that object is kvmalloc-backed and refcounted, and only put_group_info() reaches kvfree(). A plain kfree(creds) drops the wrapper and leaks the group_info allocation.

The natural fix for the leak is to call free_svc_cred(creds) before kfree(creds), but free_svc_cred() invokes put_group_info() on creds->cr_group_info unconditionally when non-NULL. The existing out_free_groups: path in gssx_dec_linux_creds() already called groups_free() on that pointer without clearing it, so once free_svc_cred() is wired in, the subsequent put_group_info() would touch freed memory.

Fix all four together:

Detalles técnicos trazas, registros y código del informe original
    gssp_accept_sec_context_upcall()
      gssx_dec_accept_sec_context()
        gssx_dec_option_array()        /* fails, count=1 data=NULL */
      data = res.options.data[0].value /* NULL deref */

  - Move the oa->count = 1 assignment below the oa->data allocation
    so it is never set when oa->data is NULL.
  - Reset oa->count to 0 at free_oa: so count and data stay
    coherent and the caller sees an empty option array.
  - Call free_svc_cred(creds) before kfree(creds) at free_creds:
    so the refcounted cr_group_info is released.  free_svc_cred()
    either NULL-guards each field explicitly (cr_group_info has
    an if() check) or delegates to a helper that is NULL-safe
    itself (kfree for the string fields, gss_mech_put() which
    guards with if(gm) at gss_mech_switch.c:342), so it is safe
    to call on a partially decoded svc_cred where only
    cr_uid/cr_gid/cr_group_info have been written and everything
    else is zero from kzalloc.
  - In gssx_dec_linux_creds()'s out_free_groups: path, release
    cr_group_info with put_group_info() rather than groups_free()
    so the teardown matches free_svc_cred()'s refcount-aware path,
    and clear the pointer so a later free_svc_cred() on the same
    creds does not release it a second time.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89544",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3cfcfc102a5e57b021b786a755a38935e357797d",
              "lessThan": "fb30241f7ccace372ee83017891549f23a715581",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3cfcfc102a5e57b021b786a755a38935e357797d",
              "lessThan": "3ff45361e9469e85c0f86b8e7b82c63e50bab8ef",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3cfcfc102a5e57b021b786a755a38935e357797d",
              "lessThan": "f85a83774d7f4e2ac71c0c384df0dfb6f7d0179a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3cfcfc102a5e57b021b786a755a38935e357797d",
              "lessThan": "5e9a94539b1ec17a89177d952badfd0d844d694a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b97c37978ca825557d331c9012e0c1ddc0e42364",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bfa9d86d39a0fe4685f90c3529aa9bd62a9d97a8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bb336cd8d5ecb69c430ebe3e7bcff68471d93fa8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "dd292e884c649f9b1c18af0ec75ca90b390cd044",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "934212a623cbab851848b6de377eb476718c3e4c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5e6013ae2c8d420faea553d363935f65badd32c3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9806c2393cd2ab0a8e7bb9ffae02ce20e3112ec4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "996997d1fb2126feda550d6adcedcbd94911fc69",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4.19.311",
              "lessThan": "4.20",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.4.273",
              "lessThan": "5.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.10.214",
              "lessThan": "5.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.153",
              "lessThan": "5.16",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.83",
              "lessThan": "6.2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.23",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.7.11",
              "lessThan": "6.8",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.8.2",
              "lessThan": "6.9",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/sunrpc/auth_gss/gss_rpc_xdr.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/sunrpc/auth_gss/gss_rpc_xdr.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:37.670",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3ff45361e9469e85c0f86b8e7b82c63e50bab8ef",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5e9a94539b1ec17a89177d952badfd0d844d694a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f85a83774d7f4e2ac71c0c384df0dfb6f7d0179a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fb30241f7ccace372ee83017891549f23a715581",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: fix gssx_dec_option_array error path bugs\n\nFour coupled defects in the gssx XDR option-array decoder make the\nerror paths unsafe: a NULL deref in the caller, a refcount leak on\nthe decoded group_info, and a latent use-after-free that the leak\nfix would otherwise expose.\n\ngssx_dec_option_array() sets oa->count = 1 before allocating\noa->data.  If that allocation fails, -ENOMEM is returned with\noa->count == 1 and oa->data == NULL.  All other error paths jump\nto free_oa: which frees oa->data and NULLs it but also leaves\noa->count == 1.  The caller trusts the count:\n\n    gssp_accept_sec_context_upcall()\n      gssx_dec_accept_sec_context()\n        gssx_dec_option_array()        /* fails, count=1 data=NULL */\n      data = res.options.data[0].value /* NULL deref */\n\nIndependently, free_creds: releases the partially decoded svc_cred\nwith a bare kfree(creds).  gssx_dec_linux_creds() installs a\ngroups_alloc() result into creds->cr_group_info; that object is\nkvmalloc-backed and refcounted, and only put_group_info() reaches\nkvfree().  A plain kfree(creds) drops the wrapper and leaks the\ngroup_info allocation.\n\nThe natural fix for the leak is to call free_svc_cred(creds) before\nkfree(creds), but free_svc_cred() invokes put_group_info() on\ncreds->cr_group_info unconditionally when non-NULL.  The existing\nout_free_groups: path in gssx_dec_linux_creds() already called\ngroups_free() on that pointer without clearing it, so once\nfree_svc_cred() is wired in, the subsequent put_group_info() would\ntouch freed memory.\n\nFix all four together:\n\n  - Move the oa->count = 1 assignment below the oa->data allocation\n    so it is never set when oa->data is NULL.\n  - Reset oa->count to 0 at free_oa: so count and data stay\n    coherent and the caller sees an empty option array.\n  - Call free_svc_cred(creds) before kfree(creds) at free_creds:\n    so the refcounted cr_group_info is released.  free_svc_cred()\n    either NULL-guards each field explicitly (cr_group_info has\n    an if() check) or delegates to a helper that is NULL-safe\n    itself (kfree for the string fields, gss_mech_put() which\n    guards with if(gm) at gss_mech_switch.c:342), so it is safe\n    to call on a partially decoded svc_cred where only\n    cr_uid/cr_gid/cr_group_info have been written and everything\n    else is zero from kzalloc.\n  - In gssx_dec_linux_creds()'s out_free_groups: path, release\n    cr_group_info with put_group_info() rather than groups_free()\n    so the teardown matches free_svc_cred()'s refcount-aware path,\n    and clear the pointer so a later free_svc_cred() on the same\n    creds does not release it a second time."
    }
  ],
  "lastModified": "2026-09-21T14:17:22.970",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}