Kestrel
대시보드로 돌아가기
CVE-2026-89537UNKNOWNMITRENVD대응게시일: 2026. 09. 11.수정일: 2026. 09. 11.CNA: 416baaa9-dc9f-4396-8d5f-8c081fb06d67Received

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2 gss

위협 신호 · CVSS · EPSS · KEV

정기 패치· 높은 악용 신호 없음
CVSS
unknown

이론적 심각도 점수

EPSS

예측 데이터 없음

KEV
미등재

실측 악용 기록 없음

권장 대응 기한60일 이내CISA SSVC 기준

계획된 패치 주기 내 조치(60일 이내)

외부 노출· KEV 미등재 · 자동화 어려움 · 부분 영향 · 외부 노출

CVSS 벡터 · 메트릭

CVSS 벡터 정보 없음

상세 설명

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2

gss_krb5_verify_mic_v2() reads the token ID at ptr[0..1], the flags
byte at ptr[2], and padding at ptr[3..7], then passes
ptr + GSS_KRB5_TOK_HDR_LEN and cksum_len to gss_krb5_mic_build_sg().
None of these accesses check read_token->len first.

The minimum safe token size is GSS_KRB5_TOK_HDR_LEN (16) plus
ctx->krb5e->cksum_len (12-24, depending on the enctype). All callers
accept shorter tokens from the wire:

  • gss_unwrap_resp_integ() enforces only an upper bound
    (offset + len <= rcv_buf->len) before allocating
    mic.data = kmalloc(len) and passing it to gss_verify_mic().
    A malicious NFS server can therefore supply a short checksum
    opaque, producing a small slab allocation that the Kerberos MIC
    verifier reads past.

  • gss_validate() enforces only len <= RPC_MAX_AUTH_SIZE (400)
    before passing the wire-supplied length to
    gss_validate_seqno_mic(), which constructs a mic xdr_netobj
    and calls gss_verify_mic().

  • svcauth_gss_verify_header() enforces only
    checksum.len >= XDR_UNIT (4 bytes) before dispatching to
    gss_verify_mic().

  • svcauth_gss_unwrap_integ() checks only that the checksum fits
    in gsd->gsd_scratch.

Add a length guard at the top of gss_krb5_verify_mic_v2(), before any
ptr[] access or scatterlist construction. Well-formed MIC tokens from
gss_krb5_get_mic_v2() already have exactly GSS_KRB5_TOK_HDR_LEN +
cksum_len bytes, so valid traffic is unaffected.

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.