PT-2026-28219 · Unknown+1 · Kgssapi.Ko+2
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FreeBSD (affected versions not specified)
Description
A stack-based buffer overflow exists in the
kgssapi.ko kernel module and the librpcgss sec library. The issue occurs during the validation of RPCSEC GSS data packets, where a routine responsible for checking the packet signature copies data into a stack buffer without verifying if the buffer is sufficiently large. This flaw can be triggered by a malicious client and does not require prior authentication.In the kernel, this allows an authenticated user to achieve remote code execution (RCE) if they can send packets to the kernel's NFS server while
kgssapi.ko is loaded. In userspace, any application that loads librpcgss sec and operates an RPC server is vulnerable to RCE from any client capable of sending packets.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd
Kgssapi.Ko
Librpcgss Sec