Impact
The vulnerability arises from the xdr_buf_trim() function in the tail of an XDR buffer by walking the tail, pages, and head iovecs. Each per‑section step uses min_t() so it never removes more bytes than the section holds, but the final accounting at the fix_len label subtracts the total bytes actually consumed from buf->len without clamping. When the caller has set buf->len to a value smaller than the sum of the iov_lens, (len - trim) can exceed buf->len and the unsigned subtraction wraps to near UINT_MAX. This wrapped buf->len propagates as the authoritative stream bound into all downstream XDR decoders. The flaw is a classic impact of integer underflow, an instance of CWE‑191 (Integer Underflow or Wraparound), and can lead to out‑of‑bounds memory access, which in turn can enable arbitrary code execution.
Affected Systems
The vulnerability impacts the Linux kernel’s SUNRPC subsystem. the any kernel not containing the patch is affected. The advisory offers only commit references, so users must verify whether their kernel build includes the changes.
Risk and Exploitability
The CVSS score of 9.8 classifies this flaw as critical severity. The EPSS score of < 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via malicious SUNRPC traffic or crafted Kerberos tokens that invoke gss_krb5_unwrap_v2. If the underflow in xdr_buf_trim() is triggered, it can cause buffer length corruption which may lead to out‑of‑bounds memory access and potentially arbitrary code execution. No exploitation prerequisites beyond the ability to send crafted requests to an affected kernel are identified.
OpenCVE Enrichment
Debian DSA