CVE-2026-89650
nicheOut-of-bounds read in Linux kernel CephFS client via malicious MDS map
The Linux kernel's CephFS client contains an out-of-bounds read in ceph_mdsmap_decode() (fs/ceph/mdsmap.c) when decoding a CEPH_MSG_MDS_MAP message whose per-MDS info records use format version 2 or 3 with an oversized num_export_targets field. The decode cursor is advanced by num_export_targets * sizeof(u32) without verifying that many bytes remain, because the info_end bounds check only applies to info_v >= 4; the subsequent export-targets loop then reads past the message buffer. The flaw is triggered by a malicious or compromised Ceph monitor, or by an on-path attacker on an unsigned/unencrypted messenger session, giving a network vector with no authentication or user interaction required (CVSS 3.1: 9.1, with high availability and confidentiality ratings per the score, though the decoded values stay in kernel memory). Any system mounting CephFS with an affected kernel is exposed, and the practical prerequisites (a rogue monitor or an unencrypted monitor-client session) limit the attacker population. No public proof of concept is known and the flaw is not listed in CISA's KEV, so exploitation is presumed absent. The fix adds a ceph_decode_need() bounds check for all info_v >= 2 and computes the byte count with size_mul() so the attacker-controlled multiplication fails closed on overflow.
What to do: Apply kernel updates containing the upstream fix (the ceph_decode_need() check in ceph_mdsmap_decode()) as soon as your distribution ships it, prioritizing hosts that mount CephFS. Ensure monitor-to-client messenger sessions use authentication and encryption (ms_mode=secure) and restrict monitor ports to trusted networks so a rogue or spoofed monitor cannot reach clients. Watch for KASAN slab-out-of-bounds reports in ceph_mdsmap_decode() on CephFS clients as an indicator of attempted triggering.
| Linux (kernel.org) Linux kernel | All kernel versions containing the vulnerable ceph_mdsmap_decode() code prior to the upstream fix; the source data does not specify exact fixed or affected vers |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In the Linux kernel, the following vulnerability has been resolved: ceph: bound num_export_targets array for mds info v2/v3 ceph_mdsmap_decode() in fs/ceph/mdsmap.c reads num_export_targets from each per-mds info record and advances the decode cursor by num_export_targets * sizeof(u32) without first checking that many bytes remain. The only upper-bound check that catches a runaway cursor (*p > info_end) is gated on info_v >= 4, because info_end is left NULL for info_v 2 and 3. When the monitor sends an MDS map whose per-mds info version is 2 or 3 with an oversized num_export_targets, the cursor moves past the message front buffer and the later export-targets loop calls the unchecked ceph_decode_32() on out-of-bounds memory. A kernel client processes CEPH_MSG_MDS_MAP from its monitor session (net/ceph/mon_client.c dispatches it; fs/ceph/super.c routes it to ceph_mdsc_handle_mdsmap(), which sets end to the front buffer bound and calls ceph_mdsmap_decode()). A malicious or compromised monitor, or an on-path attacker on an unsigned/unencrypted messenger session, can therefore drive an out-of-bounds read in the client kernel; on x86_64 with KASAN it is reported as a slab-out-of-bounds read in ceph_mdsmap_decode(). The decoded values land in the internal info->export_targets[] array, so the consequence is a kernel out-of-bounds read, not an information leak to the attacker. Impact: a malicious or compromised Ceph monitor sending an MDS map with a per-mds info version of 2 or 3 and an oversized num_export_targets field triggers an out-of-bounds read in the CephFS client kernel. Add a ceph_decode_need() for the export-targets array before advancing the cursor, so the bound is enforced for every info_v >= 2, not only info_v >= 4. This mirrors the count-then-need idiom already used for m_data_pg_pools later in the same function. Compute the export-targets byte count with size_mul() and reuse that checked length when advancing the cursor, so the attacker-controlled num_export_targets multiplication fails closed on overflow rather than relying on the later kcalloc() guard.
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.