Description
In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: reject duplicate CREDS_VALUE options

gssx_dec_option_array() walks the wire-supplied option array and, for
every entry whose name matches CREDS_VALUE, calls
gssx_dec_linux_creds() on the same struct svc_cred. That helper
unconditionally installs a fresh groups_alloc() result into
creds->cr_group_info without releasing whatever pointer was already
there:

for (i = 0; i < count; i++) {
... decode name ...
if (length == sizeof(CREDS_VALUE) &&
memcmp(p, CREDS_VALUE, sizeof(CREDS_VALUE)) == 0) {
err = gssx_dec_linux_creds(xdr, creds);
...
}
}

A reply that carries two CREDS_VALUE entries therefore overwrites
cr_group_info on the second iteration and orphans the group_info
allocated by the first call. The earlier free_creds path only
releases the last cr_group_info via free_svc_cred(), so the first
allocation's refcount stays at one and its kvmalloc-backed storage
is leaked. No in-tree caller of gssp_accept_sec_context_upcall()
expects more than one CREDS_VALUE per reply.

Fix by tracking whether a CREDS_VALUE option has already been
decoded and returning -EINVAL on any subsequent match, so the
free_creds path releases the single group_info that was installed.
Published: 2026-09-11
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via memory exhaustion
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows a crafted SUNRPC reply that contains two CREDS_VALUE options, each causing the kernel to reinstall the group information structure without freeing the previous allocation. This results in a kernel memory leak that can accumulate over time until the system runs out of memory, potentially causing a denial of service. The flaw does not expose user data or modify kernel integrity directly; it primarily reduces system availability.

Affected Systems

Linux kernels that have not incorporated. The issue resides in the kernel's handling of SUNRPC GSS authentication options.

Risk and Exploitability

An attacker can trigger the memory leak by sending a SUNRPC reply with duplicate CREDS_VALUE entries. The likely attack vector is remote exploitation of the GSS-based SUNRPC interface, though a local attacker with the ability to inject replies could also trigger the flaw. The EPSS score indicates an exploitation probability of less than 1% and the issue is not listed in the CISA KEV catalog, suggesting it is not actively targeted.

Generated by OpenCVE AI on September 21, 2026 at 01:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit that fixes the double-decoding issue.
  • If a kernel upgrade is not immediately possible, restrict or disable SUNRPC services that accept GSS authentication, or use firewall rules to block unsolicited RPC traffic.
  • Monitor kernel memory usage for abnormal increases that may indicate repeated exploitation of the leak.

Generated by OpenCVE AI on September 21, 2026 at 01:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772

Mon, 14 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Sun, 13 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Sun, 13 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
CWE-401

Sun, 13 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
CWE-401

Sat, 12 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Sat, 12 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: SUNRPC: reject duplicate CREDS_VALUE options gssx_dec_option_array() walks the wire-supplied option array and, for every entry whose name matches CREDS_VALUE, calls gssx_dec_linux_creds() on the same struct svc_cred. That helper unconditionally installs a fresh groups_alloc() result into creds->cr_group_info without releasing whatever pointer was already there: for (i = 0; i < count; i++) { ... decode name ... if (length == sizeof(CREDS_VALUE) && memcmp(p, CREDS_VALUE, sizeof(CREDS_VALUE)) == 0) { err = gssx_dec_linux_creds(xdr, creds); ... } } A reply that carries two CREDS_VALUE entries therefore overwrites cr_group_info on the second iteration and orphans the group_info allocated by the first call. The earlier free_creds path only releases the last cr_group_info via free_svc_cred(), so the first allocation's refcount stays at one and its kvmalloc-backed storage is leaked. No in-tree caller of gssp_accept_sec_context_upcall() expects more than one CREDS_VALUE per reply. Fix by tracking whether a CREDS_VALUE option has already been decoded and returning -EINVAL on any subsequent match, so the free_creds path releases the single group_info that was installed.
Title SUNRPC: reject duplicate CREDS_VALUE options
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:44:16.699Z

Reserved: 2026-09-11T19:38:34.721Z

Link: CVE-2026-89539

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:36.977

Modified: 2026-09-11T20:19:36.977

Link: CVE-2026-89539

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:16Z

Links: CVE-2026-89539 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:30:08Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime