Out-of-bounds read in Linux kernel - CVE-2026-89542
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper length validation in gss_krb5_unwrap_v2() and its rotation helpers when processing a short or malformed GSS token. A remote user can provide a token shorter than the required header or with a declared length exceeding the buffer bounds to cause a denial of service.
The flawed length arithmetic can result in an out-of-bounds read, an unsigned underflow during cleanup, or a divide-by-zero during buffer rotation.