<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 22:04:47 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-89544 — SUNRPC: fix gssx_dec_option_array error path bugs</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-89544</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;SUNRPC: fix gssx_dec_option_array error path bugs&lt;/p&gt;
&lt;p&gt;Four coupled defects in the gssx XDR option-array decoder make the
error paths unsafe: a NULL deref in the caller, a refcount leak on
the decoded group_info, and a latent use-after-free that the leak
fix would otherwise expose.&lt;/p&gt;
&lt;p&gt;gssx_dec_option_array() sets oa-&amp;gt;count = 1 before allocating
oa-&amp;gt;data.  If that allocation fails, -ENOMEM is returned with
oa-&amp;gt;count == 1 and oa-&amp;gt;data == NULL.  All other error paths jump
to free_oa: which frees oa-&amp;gt;data and NULLs it but also leaves
oa-&amp;gt;count == 1.  The caller trusts the count:&lt;/p&gt;
&lt;p&gt;gssp_accept_sec_context_upcall()
      gssx_dec_accept_sec_context()
        gssx_dec_option_array()        /* fails, count=1 data=NULL */
      data = res.options.data[0].value /* NULL deref */&lt;/p&gt;
&lt;p&gt;Independently, free_creds: releases the partially decoded svc_cred
with a bare kfree(creds).  gssx_dec_linux_creds() installs a
groups_alloc() result into creds-&amp;gt;cr_group_info; that object is
kvmalloc-backed and refcounted, and only put_group_info() reaches
kvfree().  A plain kfree(creds) drops the wrapper and leaks the
group_info allocation.&lt;/p&gt;
&lt;p&gt;The natural fix for the leak is to call free_svc_cred(creds) before
kfree(creds), but free_svc_cred() invokes put_group_info() on
creds-&amp;gt;cr_group_info unconditionally when non-NULL.  The existing
out_free_groups: path in gssx_dec_linux_creds() already called
groups_free() on that pointer without clearing i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;SUNRPC: fix gssx_dec_option_array error path bugs&lt;/p&gt;
&lt;p&gt;Four coupled defects in the gssx XDR option-array decoder make the
error paths unsafe: a NULL deref in the caller, a refcount leak on
the decoded group_info, and a latent use-after-free that the leak
fix would otherwise expose.&lt;/p&gt;
&lt;p&gt;gssx_dec_option_array() sets oa-&amp;gt;count = 1 before allocating
oa-&amp;gt;data.  If that allocation fails, -ENOMEM is returned with
oa-&amp;gt;count == 1 and oa-&amp;gt;data == NULL.  All other error paths jump
to free_oa: which frees oa-&amp;gt;data and NULLs it but also leaves
oa-&amp;gt;count == 1.  The caller trusts the count:&lt;/p&gt;
&lt;p&gt;gssp_accept_sec_context_upcall()
      gssx_dec_accept_sec_context()
        gssx_dec_option_array()        /* fails, count=1 data=NULL */
      data = res.options.data[0].value /* NULL deref */&lt;/p&gt;
&lt;p&gt;Independently, free_creds: releases the partially decoded svc_cred
with a bare kfree(creds).  gssx_dec_linux_creds() installs a
groups_alloc() result into creds-&amp;gt;cr_group_info; that object is
kvmalloc-backed and refcounted, and only put_group_info() reaches
kvfree().  A plain kfree(creds) drops the wrapper and leaks the
group_info allocation.&lt;/p&gt;
&lt;p&gt;The natural fix for the leak is to call free_svc_cred(creds) before
kfree(creds), but free_svc_cred() invokes put_group_info() on
creds-&amp;gt;cr_group_info unconditionally when non-NULL.  The existing
out_free_groups: path in gssx_dec_linux_creds() already called
groups_free() on that pointer without clearing i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-89544</guid>
    </item>
  </channel>
</rss>
