Impact
The Linux kernel’s SUNRPC authentication module enforces Kerberos security by unwrapping encrypted tokens. In the unwrapping routine, only an upper bound on the token length was previously checked, while the minimum length requirement for a valid RFC‑4121 token was omitted. A malicious actor can therefore send a token of 16 bytes or fewer; this value passes the upper‑bound test but triggers a divide‑by‑zero inside the kernel’s rotation function, resulting in a kernel panic. The vulnerability is classified as CWE‑369 and delivers a crash that brings the entire system down, effectively a denial‑of‑service to all users of the affected host.
Affected Systems
The flaw exists in any unpatched Linux kernel containing the original svcauth_gss implementation. Kernels released before the commit that added a minimum‑length check (commit 2eed1e6a) are vulnerable. Any distribution that has not yet merged this change into its kernel packages, or that packages an older kernel for stability reasons, remains at risk. System administrators should verify the kernel version on all nodes that run SUNRPC services and confirm the patch is present.
Risk and Exploitability
The CVSS score of 9.8 highlights the severity, while the EPSS score of less than 1 % indicates a low but non‑zero probability of exploitation. The vulnerability is not currently listed in CISA’s KEV catalog. An attacker would need to send a specially crafted, very short Kerberos token to a vulnerable SUNRPC service; no local privilege escalation or code execution is required. If successful, the exploit causes an immediate kernel crash and a denial‑of‑service condition for all users on the affected host.
OpenCVE Enrichment
Debian DSA