Impact
The vulnerability exploits an out‑of‑bounds read and subsequent unsigned underflow inside the Linux kernel’s SUNRPC GSS‑Kerberos decryption routine gss_krb5_unwrap_v2. A malicious token that is shorter than the required 16‑byte header causes the function to read beyond the buffer, triggers an unsigned underflow, and drives an oversized memmove that overwrites kernel memory. This allows an attacker to corrupt kernel data structures, potentially The weakness is identified as CWE‑125.
Affected Systems
All Linux kernel releases that include the SUNRPC implementation before the commit adding defensive checks to gss_krb5_unwrap_v2 are affected. The vulnerability is present in the kernel’s core SUNRPC code that parses GSS‑Kerberos tokens; no restricted product version list is provided, so any kernel older than the revision that hardens the routine is at risk.
Risk and Exploitability
The CVSS base score of 9.8 classifies this flaw as critical. The EPSS score of less than 1% indicates that strategic exploitation is currently unlikely, and the vulnerability is not listed in CISA KEV. Exploitation would require network access to a SUNRPC service that uses the vulnerable kernel function; a crafted short GSS‑Kerberos token would trigger the fault, allowing the attacker to corrupt kernel memory and obtain kernel‑level execution. The risk remains high, but widespread attacks are not yet observed.
OpenCVE Enrichment
Debian DSA