{"api_version":"1","generated_at":"2026-09-14T05:28:29+00:00","cve":"CVE-2026-89544","urls":{"html":"https://cve.report/CVE-2026-89544","api":"https://cve.report/api/cve/CVE-2026-89544.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89544","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89544"},"summary":{"title":"SUNRPC: fix gssx_dec_option_array error path bugs","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: fix gssx_dec_option_array error path bugs\n\nFour coupled defects in the gssx XDR option-array decoder make the\nerror paths unsafe: a NULL deref in the caller, a refcount leak on\nthe decoded group_info, and a latent use-after-free that the leak\nfix would otherwise expose.\n\ngssx_dec_option_array() sets oa->count = 1 before allocating\noa->data.  If that allocation fails, -ENOMEM is returned with\noa->count == 1 and oa->data == NULL.  All other error paths jump\nto free_oa: which frees oa->data and NULLs it but also leaves\noa->count == 1.  The caller trusts the count:\n\n    gssp_accept_sec_context_upcall()\n      gssx_dec_accept_sec_context()\n        gssx_dec_option_array()        /* fails, count=1 data=NULL */\n      data = res.options.data[0].value /* NULL deref */\n\nIndependently, free_creds: releases the partially decoded svc_cred\nwith a bare kfree(creds).  gssx_dec_linux_creds() installs a\ngroups_alloc() result into creds->cr_group_info; that object is\nkvmalloc-backed and refcounted, and only put_group_info() reaches\nkvfree().  A plain kfree(creds) drops the wrapper and leaks the\ngroup_info allocation.\n\nThe natural fix for the leak is to call free_svc_cred(creds) before\nkfree(creds), but free_svc_cred() invokes put_group_info() on\ncreds->cr_group_info unconditionally when non-NULL.  The existing\nout_free_groups: path in gssx_dec_linux_creds() already called\ngroups_free() on that pointer without clearing it, so once\nfree_svc_cred() is wired in, the subsequent put_group_info() would\ntouch freed memory.\n\nFix all four together:\n\n  - Move the oa->count = 1 assignment below the oa->data allocation\n    so it is never set when oa->data is NULL.\n  - Reset oa->count to 0 at free_oa: so count and data stay\n    coherent and the caller sees an empty option array.\n  - Call free_svc_cred(creds) before kfree(creds) at free_creds:\n    so the refcounted cr_group_info is released.  free_svc_cred()\n    either NULL-guards each field explicitly (cr_group_info has\n    an if() check) or delegates to a helper that is NULL-safe\n    itself (kfree for the string fields, gss_mech_put() which\n    guards with if(gm) at gss_mech_switch.c:342), so it is safe\n    to call on a partially decoded svc_cred where only\n    cr_uid/cr_gid/cr_group_info have been written and everything\n    else is zero from kzalloc.\n  - In gssx_dec_linux_creds()'s out_free_groups: path, release\n    cr_group_info with put_group_info() rather than groups_free()\n    so the teardown matches free_svc_cred()'s refcount-aware path,\n    and clear the pointer so a later free_svc_cred() on the same\n    creds does not release it a second time.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-11 20:19:37","updated_at":"2026-09-13 07:17:16"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/3ff45361e9469e85c0f86b8e7b82c63e50bab8ef","name":"https://git.kernel.org/stable/c/3ff45361e9469e85c0f86b8e7b82c63e50bab8ef","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/f85a83774d7f4e2ac71c0c384df0dfb6f7d0179a","name":"https://git.kernel.org/stable/c/f85a83774d7f4e2ac71c0c384df0dfb6f7d0179a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5e9a94539b1ec17a89177d952badfd0d844d694a","name":"https://git.kernel.org/stable/c/5e9a94539b1ec17a89177d952badfd0d844d694a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89544","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89544","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3cfcfc102a5e57b021b786a755a38935e357797d 3ff45361e9469e85c0f86b8e7b82c63e50bab8ef git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3cfcfc102a5e57b021b786a755a38935e357797d f85a83774d7f4e2ac71c0c384df0dfb6f7d0179a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3cfcfc102a5e57b021b786a755a38935e357797d 5e9a94539b1ec17a89177d952badfd0d844d694a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b97c37978ca825557d331c9012e0c1ddc0e42364 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected bfa9d86d39a0fe4685f90c3529aa9bd62a9d97a8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected bb336cd8d5ecb69c430ebe3e7bcff68471d93fa8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected dd292e884c649f9b1c18af0ec75ca90b390cd044 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 934212a623cbab851848b6de377eb476718c3e4c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5e6013ae2c8d420faea553d363935f65badd32c3 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9806c2393cd2ab0a8e7bb9ffae02ce20e3112ec4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 996997d1fb2126feda550d6adcedcbd94911fc69 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.19.311 4.20 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.4.273 5.5 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.10.214 5.11 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.15.153 5.16 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.1.83 6.2 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.6.23 6.7 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.7.11 6.8 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.8.2 6.9 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.9","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.9 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.51 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.4 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"89544","cve":"CVE-2026-89544","epss":"0.005670000","percentile":"0.452440000","score_date":"2026-09-13","updated_at":"2026-09-14 00:18:01"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/sunrpc/auth_gss/gss_rpc_xdr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"3ff45361e9469e85c0f86b8e7b82c63e50bab8ef","status":"affected","version":"3cfcfc102a5e57b021b786a755a38935e357797d","versionType":"git"},{"lessThan":"f85a83774d7f4e2ac71c0c384df0dfb6f7d0179a","status":"affected","version":"3cfcfc102a5e57b021b786a755a38935e357797d","versionType":"git"},{"lessThan":"5e9a94539b1ec17a89177d952badfd0d844d694a","status":"affected","version":"3cfcfc102a5e57b021b786a755a38935e357797d","versionType":"git"},{"status":"affected","version":"b97c37978ca825557d331c9012e0c1ddc0e42364","versionType":"git"},{"status":"affected","version":"bfa9d86d39a0fe4685f90c3529aa9bd62a9d97a8","versionType":"git"},{"status":"affected","version":"bb336cd8d5ecb69c430ebe3e7bcff68471d93fa8","versionType":"git"},{"status":"affected","version":"dd292e884c649f9b1c18af0ec75ca90b390cd044","versionType":"git"},{"status":"affected","version":"934212a623cbab851848b6de377eb476718c3e4c","versionType":"git"},{"status":"affected","version":"5e6013ae2c8d420faea553d363935f65badd32c3","versionType":"git"},{"status":"affected","version":"9806c2393cd2ab0a8e7bb9ffae02ce20e3112ec4","versionType":"git"},{"status":"affected","version":"996997d1fb2126feda550d6adcedcbd94911fc69","versionType":"git"},{"lessThan":"4.20","status":"affected","version":"4.19.311","versionType":"semver"},{"lessThan":"5.5","status":"affected","version":"5.4.273","versionType":"semver"},{"lessThan":"5.11","status":"affected","version":"5.10.214","versionType":"semver"},{"lessThan":"5.16","status":"affected","version":"5.15.153","versionType":"semver"},{"lessThan":"6.2","status":"affected","version":"6.1.83","versionType":"semver"},{"lessThan":"6.7","status":"affected","version":"6.6.23","versionType":"semver"},{"lessThan":"6.8","status":"affected","version":"6.7.11","versionType":"semver"},{"lessThan":"6.9","status":"affected","version":"6.8.2","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/sunrpc/auth_gss/gss_rpc_xdr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.9"},{"lessThan":"6.9","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.51","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.51","versionStartIncluding":"6.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.4","versionStartIncluding":"6.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"6.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19.311","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.273","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.214","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.153","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.83","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.23","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.8.2","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: fix gssx_dec_option_array error path bugs\n\nFour coupled defects in the gssx XDR option-array decoder make the\nerror paths unsafe: a NULL deref in the caller, a refcount leak on\nthe decoded group_info, and a latent use-after-free that the leak\nfix would otherwise expose.\n\ngssx_dec_option_array() sets oa->count = 1 before allocating\noa->data.  If that allocation fails, -ENOMEM is returned with\noa->count == 1 and oa->data == NULL.  All other error paths jump\nto free_oa: which frees oa->data and NULLs it but also leaves\noa->count == 1.  The caller trusts the count:\n\n    gssp_accept_sec_context_upcall()\n      gssx_dec_accept_sec_context()\n        gssx_dec_option_array()        /* fails, count=1 data=NULL */\n      data = res.options.data[0].value /* NULL deref */\n\nIndependently, free_creds: releases the partially decoded svc_cred\nwith a bare kfree(creds).  gssx_dec_linux_creds() installs a\ngroups_alloc() result into creds->cr_group_info; that object is\nkvmalloc-backed and refcounted, and only put_group_info() reaches\nkvfree().  A plain kfree(creds) drops the wrapper and leaks the\ngroup_info allocation.\n\nThe natural fix for the leak is to call free_svc_cred(creds) before\nkfree(creds), but free_svc_cred() invokes put_group_info() on\ncreds->cr_group_info unconditionally when non-NULL.  The existing\nout_free_groups: path in gssx_dec_linux_creds() already called\ngroups_free() on that pointer without clearing it, so once\nfree_svc_cred() is wired in, the subsequent put_group_info() would\ntouch freed memory.\n\nFix all four together:\n\n  - Move the oa->count = 1 assignment below the oa->data allocation\n    so it is never set when oa->data is NULL.\n  - Reset oa->count to 0 at free_oa: so count and data stay\n    coherent and the caller sees an empty option array.\n  - Call free_svc_cred(creds) before kfree(creds) at free_creds:\n    so the refcounted cr_group_info is released.  free_svc_cred()\n    either NULL-guards each field explicitly (cr_group_info has\n    an if() check) or delegates to a helper that is NULL-safe\n    itself (kfree for the string fields, gss_mech_put() which\n    guards with if(gm) at gss_mech_switch.c:342), so it is safe\n    to call on a partially decoded svc_cred where only\n    cr_uid/cr_gid/cr_group_info have been written and everything\n    else is zero from kzalloc.\n  - In gssx_dec_linux_creds()'s out_free_groups: path, release\n    cr_group_info with put_group_info() rather than groups_free()\n    so the teardown matches free_svc_cred()'s refcount-aware path,\n    and clear the pointer so a later free_svc_cred() on the same\n    creds does not release it a second time."}],"metrics":[{"cvssV3_1":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:N - The decoder runs only as a consequence of an RPCSEC_GSS_INIT/CONTINUE_INIT Call to in-kernel nfsd (and other SUNRPC servers such as lockd) on the network, typically TCP/2049. A remote client drives svcauth_gss_proxy_init() → gssp_accept_sec_context_upcall() → gssx_dec_option_array(); the attacker’s reach is purely over the network.\nAC:L - Any allocation or XDR error after oa->count is set to 1 leaves count=1 with data=NULL, and the caller always indexes res.options.data[0]. The attacker can induce those failures by flooding pre-auth GSS_INIT upcalls that each pin 256 KB of receive pages (especially under memcg-limited nfsd) and by driving large group-list replies, so success does not depend on conditions beyond their control.\nPR:N - svcauth_gss_proxy_init() runs from svcauth_gss_proc_init() on the first RPCSEC_GSS handshake leg, before the kernel has validated any Kerberos ticket. The upcall and option-array decode execute for an unauthenticated NFS client; no local account or prior credential on the server is required.\nUI:N - The crash is triggered entirely by an inbound RPC to an already-running nfsd/SUNRPC service thread. No administrator or end-user action such as mounting a filesystem or opening a file is required.\nS:U - The NULL dereference and group_info leak occur inside the host kernel’s SUNRPC/GSS code. Impact stays within that kernel’s security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:N - With oa->count==1 and oa->data==NULL, gssp_accept_sec_context_upcall() does &res.options.data[0].value, a NULL+small-offset load that faults on the unmapped zero page. No kernel memory is returned to the attacker; unlike a UAF, freed object contents are never read.\nI:N - The faulting access is a pure NULL-pointer dereference with no kernel write. The put_group_info() UAF described in the fix is only latent: the unpatched free_creds path kfree()s the svc_cred wrapper without touching cr_group_info, so the dangling pointer is not used.\nA:H - The NULL dereference oopses the nfsd (or lockd) thread and panics the host where panic_on_oops is set, which is typical on NAS/appliance NFS servers. The same error path also leaks the kvmalloc-backed group_info, and the crash can be repeated to take down SUNRPC service threads."}]}],"providerMetadata":{"dateUpdated":"2026-09-13T06:30:43.148Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/3ff45361e9469e85c0f86b8e7b82c63e50bab8ef"},{"url":"https://git.kernel.org/stable/c/f85a83774d7f4e2ac71c0c384df0dfb6f7d0179a"},{"url":"https://git.kernel.org/stable/c/5e9a94539b1ec17a89177d952badfd0d844d694a"}],"title":"SUNRPC: fix gssx_dec_option_array error path bugs","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-89544","datePublished":"2026-09-11T19:44:20.424Z","dateReserved":"2026-09-11T19:38:34.722Z","dateUpdated":"2026-09-13T06:30:43.148Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-11 20:19:37","lastModifiedDate":"2026-09-13 07:17:16","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89544","Ordinal":"1","Title":"SUNRPC: fix gssx_dec_option_array error path bugs","CVE":"CVE-2026-89544","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89544","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: fix gssx_dec_option_array error path bugs\n\nFour coupled defects in the gssx XDR option-array decoder make the\nerror paths unsafe: a NULL deref in the caller, a refcount leak on\nthe decoded group_info, and a latent use-after-free that the leak\nfix would otherwise expose.\n\ngssx_dec_option_array() sets oa->count = 1 before allocating\noa->data.  If that allocation fails, -ENOMEM is returned with\noa->count == 1 and oa->data == NULL.  All other error paths jump\nto free_oa: which frees oa->data and NULLs it but also leaves\noa->count == 1.  The caller trusts the count:\n\n    gssp_accept_sec_context_upcall()\n      gssx_dec_accept_sec_context()\n        gssx_dec_option_array()        /* fails, count=1 data=NULL */\n      data = res.options.data[0].value /* NULL deref */\n\nIndependently, free_creds: releases the partially decoded svc_cred\nwith a bare kfree(creds).  gssx_dec_linux_creds() installs a\ngroups_alloc() result into creds->cr_group_info; that object is\nkvmalloc-backed and refcounted, and only put_group_info() reaches\nkvfree().  A plain kfree(creds) drops the wrapper and leaks the\ngroup_info allocation.\n\nThe natural fix for the leak is to call free_svc_cred(creds) before\nkfree(creds), but free_svc_cred() invokes put_group_info() on\ncreds->cr_group_info unconditionally when non-NULL.  The existing\nout_free_groups: path in gssx_dec_linux_creds() already called\ngroups_free() on that pointer without clearing it, so once\nfree_svc_cred() is wired in, the subsequent put_group_info() would\ntouch freed memory.\n\nFix all four together:\n\n  - Move the oa->count = 1 assignment below the oa->data allocation\n    so it is never set when oa->data is NULL.\n  - Reset oa->count to 0 at free_oa: so count and data stay\n    coherent and the caller sees an empty option array.\n  - Call free_svc_cred(creds) before kfree(creds) at free_creds:\n    so the refcounted cr_group_info is released.  free_svc_cred()\n    either NULL-guards each field explicitly (cr_group_info has\n    an if() check) or delegates to a helper that is NULL-safe\n    itself (kfree for the string fields, gss_mech_put() which\n    guards with if(gm) at gss_mech_switch.c:342), so it is safe\n    to call on a partially decoded svc_cred where only\n    cr_uid/cr_gid/cr_group_info have been written and everything\n    else is zero from kzalloc.\n  - In gssx_dec_linux_creds()'s out_free_groups: path, release\n    cr_group_info with put_group_info() rather than groups_free()\n    so the teardown matches free_svc_cred()'s refcount-aware path,\n    and clear the pointer so a later free_svc_cred() on the same\n    creds does not release it a second time.","Type":"Description","Title":"SUNRPC: fix gssx_dec_option_array error path bugs"}]}}}