PT-2026-28219 · Unknown+1 · Librpcgss Sec+2
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FreeBSD (affected versions not specified)
Description
A stack-based buffer overflow exists in the
kgssapi.ko kernel module and the librpcgss sec library. The issue occurs during the validation of RPCSEC GSS data packets, where a routine responsible for checking the packet signature copies data into a stack buffer without verifying if the buffer is sufficiently large. This flaw can be triggered by a malicious client and does not require prior authentication.In the kernel, this allows an authenticated user to achieve remote code execution (RCE) if they can send packets to the kernel's NFS server while
kgssapi.ko is loaded. In userspace, any application that loads librpcgss sec and operates an RPC server is vulnerable to RCE from any client capable of sending packets.Recommendations
As a temporary mitigation, restrict access to the kernel's NFS server or avoid loading the
kgssapi.ko module if not required.
Restrict the use of the librpcgss sec library in userspace applications running RPC servers to minimize the risk of exploitation.Exploit
Fix
DoS
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd
Kgssapi.Ko
Librpcgss Sec