Kernel-level flaw in widely deployed Linux SUNRPC/GSS Kerberos code affecting servers and distributions; broad impact on infrastructure.
CVE-2026-89542
Linux kernel SUNRPC GSS token bug allows kernel crash or potential RCE
Is CVE-2026-89542 being exploited?
Not confirmed. CVE-2026-89542 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.52% probability of exploitation in the next 30 days.
How severe is CVE-2026-89542?
CVE-2026-89542 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-89542?
Yes. A fix has been recorded for CVE-2026-89542. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-89542 affect?
CVE-2026-89542 affects Linux kernel (SUNRPC gss_krb5_unwrap_v2), Servers using NFS/SUNRPC, Linux distributions with affected kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-89542?
Apply vendor kernel updates/backports and reboot affected hosts immediately.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Crafted SUNRPC/GSS Kerberos tokens cause OOB reads and an unsigned underflow that can trigger huge memmove, leading to kernel panic or possible privilege escalation/RCE.
Immediate action required
- affected>= de9c17eb4a912c9028f7b470eb80815144883b26 and < dddcb0f4b7e27fac16a78ea9a1c8ec2e8a241087
- affected>= de9c17eb4a912c9028f7b470eb80815144883b26 and < 806584a4b67a7233870c33e5b8f872e76dd02988
- affected>= de9c17eb4a912c9028f7b470eb80815144883b26 and < a7894e10572d53eb10109b8d07459cc8d3435811
- affected>= de9c17eb4a912c9028f7b470eb80815144883b26 and < 6959297aaa9572783d620a226d73c3fb94494888
- affected2.6.35
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.