CVE-2026-89544

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
21/09/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> SUNRPC: fix gssx_dec_option_array error path bugs<br /> <br /> Four coupled defects in the gssx XDR option-array decoder make the<br /> error paths unsafe: a NULL deref in the caller, a refcount leak on<br /> the decoded group_info, and a latent use-after-free that the leak<br /> fix would otherwise expose.<br /> <br /> gssx_dec_option_array() sets oa-&gt;count = 1 before allocating<br /> oa-&gt;data. If that allocation fails, -ENOMEM is returned with<br /> oa-&gt;count == 1 and oa-&gt;data == NULL. All other error paths jump<br /> to free_oa: which frees oa-&gt;data and NULLs it but also leaves<br /> oa-&gt;count == 1. The caller trusts the count:<br /> <br /> gssp_accept_sec_context_upcall()<br /> gssx_dec_accept_sec_context()<br /> gssx_dec_option_array() /* fails, count=1 data=NULL */<br /> data = res.options.data[0].value /* NULL deref */<br /> <br /> Independently, free_creds: releases the partially decoded svc_cred<br /> with a bare kfree(creds). gssx_dec_linux_creds() installs a<br /> groups_alloc() result into creds-&gt;cr_group_info; that object is<br /> kvmalloc-backed and refcounted, and only put_group_info() reaches<br /> kvfree(). A plain kfree(creds) drops the wrapper and leaks the<br /> group_info allocation.<br /> <br /> The natural fix for the leak is to call free_svc_cred(creds) before<br /> kfree(creds), but free_svc_cred() invokes put_group_info() on<br /> creds-&gt;cr_group_info unconditionally when non-NULL. The existing<br /> out_free_groups: path in gssx_dec_linux_creds() already called<br /> groups_free() on that pointer without clearing it, so once<br /> free_svc_cred() is wired in, the subsequent put_group_info() would<br /> touch freed memory.<br /> <br /> Fix all four together:<br /> <br /> - Move the oa-&gt;count = 1 assignment below the oa-&gt;data allocation<br /> so it is never set when oa-&gt;data is NULL.<br /> - Reset oa-&gt;count to 0 at free_oa: so count and data stay<br /> coherent and the caller sees an empty option array.<br /> - Call free_svc_cred(creds) before kfree(creds) at free_creds:<br /> so the refcounted cr_group_info is released. free_svc_cred()<br /> either NULL-guards each field explicitly (cr_group_info has<br /> an if() check) or delegates to a helper that is NULL-safe<br /> itself (kfree for the string fields, gss_mech_put() which<br /> guards with if(gm) at gss_mech_switch.c:342), so it is safe<br /> to call on a partially decoded svc_cred where only<br /> cr_uid/cr_gid/cr_group_info have been written and everything<br /> else is zero from kzalloc.<br /> - In gssx_dec_linux_creds()&amp;#39;s out_free_groups: path, release<br /> cr_group_info with put_group_info() rather than groups_free()<br /> so the teardown matches free_svc_cred()&amp;#39;s refcount-aware path,<br /> and clear the pointer so a later free_svc_cred() on the same<br /> creds does not release it a second time.