Impact
The Linux kernel's SUNRPC implementationgss_krb5_verify_mic_v2() routine. The code reads fields of a Kerberos MIC token (token ID, flags, padding) without first verifying that the supplied buffer is large enough (CWE-125). A malicious NFS server can send a short MIC token, causing the kernel to read past the end of the buffer, which can leak kernel memory. This vulnerability does not directly provide remote code execution but can be leveraged for further attacks.
Affected Systems
All Linux kernels released prior to the commit that added a length guard to gss_krb5_verify_mic_v2() are vulnerable. TheFS mounts, regardless of kernel minor version.
Risk and Exploitability
A likely attacker is a compromised or malicious NFS server that transmits malformed MIC tokens over the network. The CVSS score of 9.1 indicates high severity, while an EPSS score of <1% suggests exploitation is rare at present. Although the vulnerability is not in the CISA KEV catalog, the combination of network exposure and potential kernel memory disclosure still represents a significant risk for exposed servers.
OpenCVE Enrichment