{"id":"CVE-2026-93207","published":"2026-09-24T16:17:15.357","lastModified":"2026-09-25T05:16:58.630","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry\n\nsvcauth_gss_decode_credbody() writes the caller's\nrpc_gss_wire_cred field by field and assigns gc_ctx.len only on\nthe success tail.  The caller storage is svcdata->clcred, which\nlives in the per-svc_rqst gss_svc_data and is reused across\nrequests.  Early decode failures leave partially decoded state\nmixed with residue from the prior request.\n\nThe trailing body_len tightness check is the sharpest case:\nxdr_stream_decode_opaque_inline() has already written gc_ctx.data\nwith a borrowed inline pointer into the current request's XDR\npages, but gc_ctx.len retains its prior value.  Once the request\npages are released the pooled clcred carries a dangling pointer\npaired with a stale length.\n\nZero the caller's rpc_gss_wire_cred at function entry so that\nevery early-return path leaves a deterministic all-zero cred.\nOn the trailing tightness-check path, gc_ctx.len is now zero\ninstead of stale, which neuters length-driven consumers such as\ngss_svc_searchbyctx() that would otherwise walk the dangling\ndata pointer.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/0e18641708eaa8bc3c1ff338cd844aeadbd52bac","tags":[]},{"url":"https://git.kernel.org/stable/c/0fa8a8acae57e6373962741d5b06d13f44aba6a9","tags":[]},{"url":"https://git.kernel.org/stable/c/11539e8fcce0b0af062ae5fecf7b3676c2f7aeed","tags":[]},{"url":"https://git.kernel.org/stable/c/56b29d62017c7dd1718d060dd5b3a2ce61095d0c","tags":[]},{"url":"https://git.kernel.org/stable/c/e0778464049b0238f2915a40007a4154f86cf351","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This flaw allows an attacker to exploit a race condition in the Linux kernel's SUNRPC implementation, leading to potential memory corruption or privilege escalation.","exploitability":"Exploitation requires precise timing and control over RPC requests, making it moderately difficult. Precondition is the presence of a vulnerable SUNRPC service.","blast_radius":"If exploited, the impact could be severe, potentially allowing an attacker to gain unauthorized access or execute arbitrary code on the system.","remediation":"Upgrade to the Linux kernel version 6.1.17 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["kernel","rpc","memory-corruption"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:52:24.111Z"}}