{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  SUNRPC: fix gssx_dec_option_array error path bugs  Four coupled defects in the gssx XDR option-array decoder make the error paths unsafe: a NULL deref in the caller, a refcount leak on the decoded group_info, and a latent use-after-free that the leak fix would otherwise expose.  gssx_dec_option_array() sets oa-\u003ecount = 1 before allocating oa-\u003edata.  If that allocation fails, -ENOMEM is returned with oa-\u003ecount == 1 and oa-\u003edata == NULL.  All other error paths jump to free_oa: which frees oa-\u003edata and NULLs it but also leaves oa-\u003ecount == 1.  The caller trusts the count:      gssp_accept_sec_context_upcall()       gssx_dec_accept_sec_context()         gssx_dec_option_array()        /* fails, count=1 data=NULL */       data = res.options.data[0].value /* NULL deref */  Independently, free_creds: releases the partially decoded svc_cred with a bare kfree(creds).  gssx_dec_linux_creds() installs a groups_alloc() result into creds-\u003ecr_group_info; that object is kvmalloc-backed and refcounted, and only put_group_info() reaches kvfree().  A plain kfree(creds) drops the wrapper and leaks the group_info allocation.  The natural fix for the leak is to call free_svc_cred(creds) before kfree(creds), but free_svc_cred() invokes put_group_info() on creds-\u003ecr_group_info unconditionally when non-NULL.  The existing out_free_groups: path in gssx_dec_linux_creds() already called groups_free() on that pointer without clearing it, so once free_svc_cred() is wired in, the subsequent put_group_info() would touch freed memory.  Fix all four together:    - Move the oa-\u003ecount = 1 assignment below the oa-\u003edata allocation     so it is never set when oa-\u003edata is NULL.   - Reset oa-\u003ecount to 0 at free_oa: so count and data stay     coherent and the caller sees an empty option array.   - Call free_svc_cred(creds) before kfree(creds) at free_creds:     so the refcounted cr_group_info is released.  free_svc_cred()     either NULL-guards each field explicitly (cr_group_info has     an if() check) or delegates to a helper that is NULL-safe     itself (kfree for the string fields, gss_mech_put() which     guards with if(gm) at gss_mech_switch.c:342), so it is safe     to call on a partially decoded svc_cred where only     cr_uid/cr_gid/cr_group_info have been written and everything     else is zero from kzalloc.   - In gssx_dec_linux_creds()'s out_free_groups: path, release     cr_group_info with put_group_info() rather than groups_free()     so the teardown matches free_svc_cred()'s refcount-aware path,     and clear the pointer so a later free_svc_cred() on the same     creds does not release it a second time.",
  "id": "DEBIAN-CVE-2026-89544",
  "modified": "2026-09-14T08:47:32.658673747Z",
  "published": "2026-09-11T20:19:37.670Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89544"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89544"
  ]
}