CVE
CVE-2026-93207
CWE
Not mapped
Affected Surface
- Linux servers that expose NFS or other SUNRPC services with RPCSEC_GSS or Kerberos enabled and still run vulnerable kernels
Welcome to Corgea’s weekly briefing. The briefing covers the most important security findings and research from the week.
This edition covers research published from Wednesday, 23 September through Tuesday, 29 September 2026, excluding items already covered in the 22 September briefing, the late-week 25 September briefing, and the follow-up 26 September briefing. After those earlier roundups pulled in Graphalgo, MemTensor, and the actions-cool reactivation, one new Corgea research article remains in scope for this Tuesday edition.
Top Article
CVE-2026-93207 leaves Linux SUNRPC with a stale GSS credential pointer
This week’s remaining lead story is CVE-2026-93207, a critical Linux kernel bug in the server-side SUNRPC GSS credential decoder. The public CVE record and upstream fix trail cited in Corgea’s write-up do not name an outside finder, so the cleanest public attribution stays with the upstream Linux maintainers who shipped the svcauth_gss_decode_credbody() state-reset fix in commit 11539e8fcce0. What matters for subscribers is the bug class: a malformed RPCSEC_GSS credential can leave reused server state holding a borrowed pointer from the current request plus a stale length from an older one, which turns what should have been a parser rejection into a remote kernel memory-corruption path on exposed SUNRPC services.
It is worth reading this article beside Corgea’s earlier Linux work on CVE-2026-53362 Linux UDPv6 fraggap, SCTPhantom, and Dirty Frag. The affected subsystems differ, but the operational lesson is the same: once an attacker reaches a trusted kernel networking boundary, the distance between “service bug” and “host compromise” can get very short.
More news
No additional uncovered English-language Corgea research articles were published in the Wednesday, 23 September through Tuesday, 29 September window after the 25 September briefing and 26 September briefing already summarized the week’s earlier package and CI incidents.
Other news:
- MemTensor’s OpenClaw plugin and MemoryOS launched the sckit implant from npm and PyPI was already covered in the 26 September briefing. Aikido first flagged the compromise, Socket mapped the runtime behavior, and StepSecurity added the clearest maintainer-side CI-bridge detail.
- Graphalgo reached Terraform providers and Go modules with trigger-gated Go malware was already covered in the 25 September briefing. Aikido deserves the public-disclosure credit, while the Corgea write-up explains why Terraform and Go dependencies often land closer to production credentials than ordinary npm tooling.
- Re-enabled
actions-cooltags turned old Mini Shai-Hulud commits back into live CI malware also landed in the 25 September briefing. Socket surfaced the September reactivation, and StepSecurity’s earlier teardown remains the clearest public explanation of how the action readRunner.Workermemory and exposed secrets. - For adjacent Linux context, compare
CVE-2026-93207with Corgea’s research on the September Linux KEV additions, CVE-2026-53362 Linux UDPv6 fraggap, and Fragnesia if you are scoping exposed engineering hosts rather than package ecosystems.
From research to remediation
Check whether this pattern exists in your codebase
Turn this research into a remediation workflow. Use AI-native static analysis to find similar application vulnerabilities and generate review-ready fixes.