{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  SUNRPC: harden gss_krb5_unwrap_v2 against short tokens  gss_krb5_unwrap_v2() reads the EC and RRC header fields at ptr+4 and ptr+6 before validating that the token is at least GSS_KRB5_TOK_HDR_LEN (16) bytes long, and its rotate_left() helper passes buf-\u003elen - base to xdr_buf_subsegment() without verifying that base \u003c= buf-\u003elen. When a caller hands in a sub-16-byte token, or a token whose declared len leaves base past the end of the buffer, three distinct failures follow:      gss_krb5_unwrap_v2(offset, len, buf)       ptr = buf-\u003ehead[0].iov_base + offset       ec  = *(ptr + 4)              /* OOB read on short head */       rrc = *(ptr + 6)              /* OOB read on short head */       rotate_left(offset + 16, buf, rrc)         xdr_buf_subsegment(buf, \u0026subbuf,                            base, buf-\u003elen - base)   /* u32 wrap when base \u003e len */         _rotate_left(\u0026subbuf, shift)           shift %= buf-\u003elen         /* divide-by-zero when base == len */  After decryption, the cleanup arithmetic has the same shape:      movelen = min_t(unsigned int, buf-\u003ehead[0].iov_len, len);     movelen -= offset + GSS_KRB5_TOK_HDR_LEN + headskip;     BUG_ON(offset + GSS_KRB5_TOK_HDR_LEN + headskip + movelen \u003e                                             buf-\u003ehead[0].iov_len);  The BUG_ON re-adds the value just subtracted, so it reduces to min(A, B) \u003e A and is permanently false; it cannot catch the unsigned underflow of movelen, which then drives a ~UINT_MAX-byte memmove().  Add four defense-in-depth guards inside the unwrap core so it is safe regardless of what its callers validate:    - reject tokens with len - offset \u003c GSS_KRB5_TOK_HDR_LEN before     touching ptr+4/ptr+6;   - bail from rotate_left() when buf-\u003elen \u003c= base, covering both the     underflow and zero-length cases;   - return early from _rotate_left() when buf-\u003elen is zero, so the     shift %= buf-\u003elen modulo cannot fault;   - replace the dead BUG_ON with a live check that returns     GSS_S_DEFECTIVE_TOKEN before the movelen subtraction.",
  "id": "DEBIAN-CVE-2026-89542",
  "modified": "2026-09-15T08:47:35.056418294Z",
  "published": "2026-09-11T20:19:37.380Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89542"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89542"
  ]
}