Impact
The vulnerability allows a crafted SUNRPC reply that contains two CREDS_VALUE options, each causing the kernel to reinstall the group information structure without freeing the previous allocation. This results in a kernel memory leak that can accumulate over time until the system runs out of memory, potentially causing a denial of service. The flaw does not expose user data or modify kernel integrity directly; it primarily reduces system availability.
Affected Systems
Linux kernels that have not incorporated. The issue resides in the kernel's handling of SUNRPC GSS authentication options.
Risk and Exploitability
An attacker can trigger the memory leak by sending a SUNRPC reply with duplicate CREDS_VALUE entries. The likely attack vector is remote exploitation of the GSS-based SUNRPC interface, though a local attacker with the ability to inject replies could also trigger the flaw. The EPSS score indicates an exploitation probability of less than 1% and the issue is not listed in the CISA KEV catalog, suggesting it is not actively targeted.
OpenCVE Enrichment
Debian DSA