Database/Kernel, userspace & hypervisor
Linux kernel SUNRPC server GSS auth (svcauth_gss_decode_credbody): svcauth_gss_decode_credbody() fills the caller's
Impact
svcauth_gss_decode_credbody() fills the caller's rpc_gss_wire_cred field by field and only sets gc_ctx.len on the success path. The storage is svcdata->clcred in the per-svc_rqst gss_svc_data, which is reused across requests, so an early decode failure leaves fresh partial state mixed with residue from the previous request. On the trailing body_len check in particular, gc_ctx.data already holds a borrowed inline pointer into the current request's XDR pages while gc_ctx.len still holds the old value; once those pages are released the pooled cred carries a dangling pointer with a stale length, which length-driven consumers such as gss_svc_searchbyctx() will walk. This affects nodes acting as a kernel NFS server with Kerberos (sec=krb5*) - shared dataset and home-directory servers in a GPU cluster - and is reachable by any client that can send a malformed RPCSEC_GSS credential.
Who can reach it
Any host that can reach the kernel NFS server's RPC port and send a malformed RPCSEC_GSS cred body. No valid Kerberos credential is needed, since the fault is on the decode-failure path. Only affects servers exporting with krb5 security.
What to do
Take the stable-kernel fix on NFS server nodes (five stable branches carry it) and reboot. There is no runtime toggle short of dropping krb5 security from exports, which is not a realistic mitigation for most sites. NFS clients are not affected.
References
Related entries
- Linux kernel (drivers/pci/controller/dwc): A PCIe BAR window can end up larger than the memory actually backing it, soCVE-2024-58006 · Linux kernel (drivers/pci/controller/dwc)Critical
- Linux kernel (net/core, net/tls): The bitmap that marks sk_msg scatterlist entries as externally owned was not carriedCVE-2026-63830 · Linux kernel (net/core, net/tls)Critical
- Proxmox VE: unauthenticated API login bypass via arbitrary tfa-challenge yields root@pamCVE-2023-54391 · Proxmox VE libpve-access-control (API ticket endpoint, tfa-challenge)Critical
- VMware ESXi / Workstation / Fusion: Use-after-free in the XHCI USB controllerCVE-2024-22252 · VMware ESXi / Workstation / FusionCritical
- VMware ESXi / Workstation / Fusion: Use-after-free in the UHCI USB controllerCVE-2024-22253 · VMware ESXi / Workstation / FusionCritical
- VMware ESXi / Workstation: TOCTOU race leading to an out-of-bounds write in VMX - full VM escape to host code executionCVE-2025-22224 · VMware ESXi / WorkstationCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.