Improper input validation in Linux kernel - CVE-2026-89538
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in gss_krb5_unwrap_v2() when processing Kerberos v2 wrap tokens with oversized extra count fields. A remote user can send a malformed Kerberos v2 wrap token to cause a denial of service.
The token must be encrypted using a valid GSS context.