{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-68153","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-30T09:28:09.371Z","datePublished":"2026-08-10T11:59:19.302Z","dateUpdated":"2026-08-19T16:30:18.048Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-19T16:30:18.048Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: remove debugfs files before client teardown\n\nceph_destroy_client() tears down the monitor client before removing\nthe per-client debugfs files. A concurrent read of the monmap debugfs\nfile can enter monmap_show() after ceph_monc_stop() has freed\nmonc->monmap, triggering a use-after-free.\n\nRemove the debugfs files before stopping the OSD and monitor clients.\ndebugfs_remove() drains active handlers and prevents new accesses, so\nthe debugfs callbacks can no longer race the rest of client teardown."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires local access to debugfs via read() on /sys/kernel/debug/ceph/client*/monmap concurrent with local ceph client teardown via umount or rbd unmap; the bug is not reachable through Ceph network protocol handlers.\nAC:L - The attacker controls both sides of the race by concurrently reading the monmap debugfs file while triggering ceph_destroy_client() via umount/rbd teardown, and can retry until the window between ceph_monc_stop() and debugfs removal is hit.\nPR:L - An unprivileged local user can use user-namespace capabilities (CAP_DAC_READ_SEARCH) to read root-owned debugfs files and race reads against libceph client teardown during automated volume detach or service restarts on Ceph storage nodes.\nUI:N - No victim user interaction is required; a local attacker can independently issue debugfs reads and trigger or time against client teardown without requiring another user to click, open files, or mount filesystems.\nS:U - The use-after-free corrupts kernel heap memory within the same kernel security domain and does not cross VM, container, or IOMMU boundaries; impact is standard kernel privilege escalation or crash.\nC:H - The use-after-free on monc->monmap permits reading freed heap memory containing monitor addresses and entity metadata, and UAF primitives are routinely leveraged for arbitrary kernel memory disclosure.\nI:H - Heap use-after-free on the variable-length ceph_monmap structure enables memory corruption that can be groomed into arbitrary kernel write primitives and local privilege escalation via control-flow hijacking.\nA:H - Concurrent access to freed monmap memory during debugfs iteration can cause kernel oops, BUG, or panic, and UAF corruption reliably threatens system availability even when full exploitation is not attempted."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/ceph/ceph_common.c"],"versions":[{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"ac78549d186090ee7125d28c3a8c376573b36194","status":"affected","versionType":"git"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"463a264e9094384112a5c8b46f0a9ddaf8566904","status":"affected","versionType":"git"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"fe46b7e06f14f6f94766832df309b249cb689d27","status":"affected","versionType":"git"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"fc1010e7e0204ece6cc0f9af4f473e9553535eab","status":"affected","versionType":"git"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"d3dc8889d39a676bf840132bd5c5c48cb0daba23","status":"affected","versionType":"git"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"8f5a3abc54ba24dbceb14cc3a719908c4f688091","status":"affected","versionType":"git"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"b9fedda2f628e030384228de0dafc574b7fb0c2f","status":"affected","versionType":"git"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"e4c804726c4afce3ba648b982d564f6af2cfa328","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/ceph/ceph_common.c"],"versions":[{"version":"2.6.34","status":"affected"},{"version":"0","lessThan":"2.6.34","status":"unaffected","versionType":"semver"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34","versionEndExcluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34","versionEndExcluding":"6.6.148"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34","versionEndExcluding":"6.12.101"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34","versionEndExcluding":"6.18.42"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34","versionEndExcluding":"7.1.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ac78549d186090ee7125d28c3a8c376573b36194"},{"url":"https://git.kernel.org/stable/c/463a264e9094384112a5c8b46f0a9ddaf8566904"},{"url":"https://git.kernel.org/stable/c/fe46b7e06f14f6f94766832df309b249cb689d27"},{"url":"https://git.kernel.org/stable/c/fc1010e7e0204ece6cc0f9af4f473e9553535eab"},{"url":"https://git.kernel.org/stable/c/d3dc8889d39a676bf840132bd5c5c48cb0daba23"},{"url":"https://git.kernel.org/stable/c/8f5a3abc54ba24dbceb14cc3a719908c4f688091"},{"url":"https://git.kernel.org/stable/c/b9fedda2f628e030384228de0dafc574b7fb0c2f"},{"url":"https://git.kernel.org/stable/c/e4c804726c4afce3ba648b982d564f6af2cfa328"}],"title":"libceph: remove debugfs files before client teardown","x_generator":{"engine":"bippy-1.2.0"}}}}