Impact
The Linux kernel contains four error‑path bugs in the SUNRPC gssx XDR option‑array decoder. A failure to allocate the data array sets the count to one, causing a NULL dereference when the caller later accesses the data. A separate bug leaks the partially decoded service credential’s group information reference count, and a latent use‑after‑free can occur when the credential is freed twice. These defects allow an attacker to corrupt kernel memory, potentially causing a system crash or enabling execution of arbitrary code with elevated privileges. The flaw involves a pointer dereference (CWE‑476).
Affected Systems
The generic Linux kernel’s SUNRPC subsystem is affected. Specific version information is not provided by the CNA, so the scope of impacted releases cannot be determined from the available data.
Risk and Exploitability
The CVSS score of 7.5 combined with an EPSS score of < 1% indicates a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via crafted SUNRPC traffic sent to the affected subsystem from an untrusted source, which could lead to memory corruption or privilege escalation on the host.
OpenCVE Enrichment
Debian DSA