Impact
The Linux kernel’s SUNRPC implementation processes Kerberos v2 wrap tokens by setting a logical buffer length that may be much smaller than the allocated receive-page capacity, then trimming the buffer based on the 16-bit "extra count" (ec) field of the token header. Even though the ec value is authenticated a token whose ec exceeds the plaintext length, structural violation per RFC 4121. This trim operation can underflow, leaving the buffer zero-length and its I/O vector lengths inconsistent, which may lead to memory corruption and a kernel crash. The result is a denial‑of‑service that can terminate privileged processes.
Affected Systems
All Linux kernel distributions are affected, as the CPE matches any Linux kernel. Because no specific version ranges are listed, any system running an un fix is applied.
Risk and Exploitability
The CVSS score of 9.8 reflects the high severity of a kernel crash. The EPSS score of less than 1% indicates that active exploitation is currently unlikely, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires a valid Kerberos authentication session on a SUNRPC service, so the attack is limited to remote network actors who can send a malformed Kerberos v2 wrap token to an RPC endpoint. By doing so an attacker can trigger the kernel crash, resulting in a denial‑of‑service that disrupts privileged processes.
OpenCVE Enrichment
Debian DSA