PT-2026-90367 · Linux · Linux
CVE-2026-89651
·
Published
2026-09-11
·
Updated
2026-09-11
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ceph: bound MDSCapAuth path and fs name decode in handle session()
handle session() decodes the MDSCapAuth records carried by a
CEPH SESSION OPEN message (msg version >= 6). For each record the
match.path and match.fs name byte strings are read by first decoding a
32-bit length and then copying that many bytes with the bare
ceph decode copy(). Unlike the surrounding fields, which all use the
safe decode variants, these two copies are not preceded by a
ceph decode need() bounds check, and the enclosing MDSCapAuth and
MDSCapMatch struct len fields are skipped rather than enforced as an
upper bound. A length larger than the bytes remaining in the message
front makes ceph decode copy() read past the end of the front buffer.
The message front is a dedicated allocation (ceph msg new2() ->
kvmalloc), so the over-read runs off that object. A malicious or
compromised MDS can trigger this with the first post-connect message on
mount, with no client-side user interaction; under KASAN it is reported
as a slab-out-of-bounds read in handle session().
Impact: a malicious MDS can force the kernel client to read up to 4 GiB
past the message front allocation during session setup, crashing the
client (out-of-bounds read).
Switch both copies to ceph decode copy safe(), which performs the
ceph decode need() bounds check before the copy and branches to the
existing bad label, matching the rest of the decoder and the error path
that frees the partially decoded cap auths array.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux