Division by zero in Linux kernel - CVE-2026-89550
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in svcauth_gss_unwrap_priv() when handling a crafted short krb5 token. A remote user can send a crafted token that triggers a division by zero to cause a denial of service.
The issue affects krb5 v2 contexts.