ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
Summary
| CVE | CVE-2026-89653 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:19:51 UTC |
| Updated | 2026-09-11 20:19:51 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
MDSMap export_targets entries are monitor controlled. check_new_map()
uses each entry as a bit number in a fixed stack bitmap, so a rank
outside the protocol namespace can make set_bit() write past the end of
the array.
Reject ranks outside CEPH_MAX_MDS while decoding the map. Do not
validate against possible_max_rank here because maps may legitimately
reference ranks beyond a temporarily reduced max_mds. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected d517b3983dd3106ca92d6c5d0d09415a4a09481c 736adee11af36e407ed902264f8b2fb5cf94b62f git |
Not specified |
| CNA |
Linux |
Linux |
affected d517b3983dd3106ca92d6c5d0d09415a4a09481c 4d298880f82c42383b36946bafde7ccf4d804c9b git |
Not specified |
| CNA |
Linux |
Linux |
affected d517b3983dd3106ca92d6c5d0d09415a4a09481c 96c3f5fbb0d5386e7111426f047f98cec4586674 git |
Not specified |
| CNA |
Linux |
Linux |
affected d517b3983dd3106ca92d6c5d0d09415a4a09481c aedc9053d909508a5f56c3f49f885fc030df4730 git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.15 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.109 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.50 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.4 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/96c3f5fbb0d5386e7111426f047f98cec4586674 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/aedc9053d909508a5f56c3f49f885fc030df4730 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/736adee11af36e407ed902264f8b2fb5cf94b62f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/4d298880f82c42383b36946bafde7ccf4d804c9b |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.