PT-2026-90367 · Linux · Linux

CVE-2026-89651

·

Published

2026-09-11

·

Updated

2026-09-11

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ceph: bound MDSCapAuth path and fs name decode in handle session()
handle session() decodes the MDSCapAuth records carried by a CEPH SESSION OPEN message (msg version >= 6). For each record the match.path and match.fs name byte strings are read by first decoding a 32-bit length and then copying that many bytes with the bare ceph decode copy(). Unlike the surrounding fields, which all use the safe decode variants, these two copies are not preceded by a ceph decode need() bounds check, and the enclosing MDSCapAuth and MDSCapMatch struct len fields are skipped rather than enforced as an upper bound. A length larger than the bytes remaining in the message front makes ceph decode copy() read past the end of the front buffer.
The message front is a dedicated allocation (ceph msg new2() -> kvmalloc), so the over-read runs off that object. A malicious or compromised MDS can trigger this with the first post-connect message on mount, with no client-side user interaction; under KASAN it is reported as a slab-out-of-bounds read in handle session().
Impact: a malicious MDS can force the kernel client to read up to 4 GiB past the message front allocation during session setup, crashing the client (out-of-bounds read).
Switch both copies to ceph decode copy safe(), which performs the ceph decode need() bounds check before the copy and branches to the existing bad label, matching the rest of the decoder and the error path that frees the partially decoded cap auths array.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-89651

Affected Products

Linux