critical

CVE

CVE-2026-93207

CWE

Not mapped

Affected Surface

  • Linux servers that expose NFS or other SUNRPC services with RPCSEC_GSS or Kerberos enabled and still run vulnerable kernels

Welcome to Corgea’s weekly briefing. The briefing covers the most important security findings and research from the week.

This edition covers research published from Wednesday, 23 September through Tuesday, 29 September 2026, excluding items already covered in the 22 September briefing, the late-week 25 September briefing, and the follow-up 26 September briefing. After those earlier roundups pulled in Graphalgo, MemTensor, and the actions-cool reactivation, one new Corgea research article remains in scope for this Tuesday edition.

Top Article

CVE-2026-93207 leaves Linux SUNRPC with a stale GSS credential pointer

This week’s remaining lead story is CVE-2026-93207, a critical Linux kernel bug in the server-side SUNRPC GSS credential decoder. The public CVE record and upstream fix trail cited in Corgea’s write-up do not name an outside finder, so the cleanest public attribution stays with the upstream Linux maintainers who shipped the svcauth_gss_decode_credbody() state-reset fix in commit 11539e8fcce0. What matters for subscribers is the bug class: a malformed RPCSEC_GSS credential can leave reused server state holding a borrowed pointer from the current request plus a stale length from an older one, which turns what should have been a parser rejection into a remote kernel memory-corruption path on exposed SUNRPC services.

It is worth reading this article beside Corgea’s earlier Linux work on CVE-2026-53362 Linux UDPv6 fraggap, SCTPhantom, and Dirty Frag. The affected subsystems differ, but the operational lesson is the same: once an attacker reaches a trusted kernel networking boundary, the distance between “service bug” and “host compromise” can get very short.

More news

No additional uncovered English-language Corgea research articles were published in the Wednesday, 23 September through Tuesday, 29 September window after the 25 September briefing and 26 September briefing already summarized the week’s earlier package and CI incidents.

Other news:

From research to remediation

Check whether this pattern exists in your codebase

Turn this research into a remediation workflow. Use AI-native static analysis to find similar application vulnerabilities and generate review-ready fixes.

References