CVE-2026-89544
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
SUNRPC: fix gssx_dec_option_array error path bugs<br />
<br />
Four coupled defects in the gssx XDR option-array decoder make the<br />
error paths unsafe: a NULL deref in the caller, a refcount leak on<br />
the decoded group_info, and a latent use-after-free that the leak<br />
fix would otherwise expose.<br />
<br />
gssx_dec_option_array() sets oa->count = 1 before allocating<br />
oa->data. If that allocation fails, -ENOMEM is returned with<br />
oa->count == 1 and oa->data == NULL. All other error paths jump<br />
to free_oa: which frees oa->data and NULLs it but also leaves<br />
oa->count == 1. The caller trusts the count:<br />
<br />
gssp_accept_sec_context_upcall()<br />
gssx_dec_accept_sec_context()<br />
gssx_dec_option_array() /* fails, count=1 data=NULL */<br />
data = res.options.data[0].value /* NULL deref */<br />
<br />
Independently, free_creds: releases the partially decoded svc_cred<br />
with a bare kfree(creds). gssx_dec_linux_creds() installs a<br />
groups_alloc() result into creds->cr_group_info; that object is<br />
kvmalloc-backed and refcounted, and only put_group_info() reaches<br />
kvfree(). A plain kfree(creds) drops the wrapper and leaks the<br />
group_info allocation.<br />
<br />
The natural fix for the leak is to call free_svc_cred(creds) before<br />
kfree(creds), but free_svc_cred() invokes put_group_info() on<br />
creds->cr_group_info unconditionally when non-NULL. The existing<br />
out_free_groups: path in gssx_dec_linux_creds() already called<br />
groups_free() on that pointer without clearing it, so once<br />
free_svc_cred() is wired in, the subsequent put_group_info() would<br />
touch freed memory.<br />
<br />
Fix all four together:<br />
<br />
- Move the oa->count = 1 assignment below the oa->data allocation<br />
so it is never set when oa->data is NULL.<br />
- Reset oa->count to 0 at free_oa: so count and data stay<br />
coherent and the caller sees an empty option array.<br />
- Call free_svc_cred(creds) before kfree(creds) at free_creds:<br />
so the refcounted cr_group_info is released. free_svc_cred()<br />
either NULL-guards each field explicitly (cr_group_info has<br />
an if() check) or delegates to a helper that is NULL-safe<br />
itself (kfree for the string fields, gss_mech_put() which<br />
guards with if(gm) at gss_mech_switch.c:342), so it is safe<br />
to call on a partially decoded svc_cred where only<br />
cr_uid/cr_gid/cr_group_info have been written and everything<br />
else is zero from kzalloc.<br />
- In gssx_dec_linux_creds()&#39;s out_free_groups: path, release<br />
cr_group_info with put_group_info() rather than groups_free()<br />
so the teardown matches free_svc_cred()&#39;s refcount-aware path,<br />
and clear the pointer so a later free_svc_cred() on the same<br />
creds does not release it a second time.
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA


