{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89653","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.742Z","datePublished":"2026-09-11T19:45:43.261Z","dateUpdated":"2026-09-14T12:01:48.132Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:01:48.132Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode\n\nMDSMap export_targets entries are monitor controlled. check_new_map()\nuses each entry as a bit number in a fixed stack bitmap, so a rank\noutside the protocol namespace can make set_bit() write past the end of\nthe array.\n\nReject ranks outside CEPH_MAX_MDS while decoding the map. Do not\nvalidate against possible_max_rank here because maps may legitimately\nreference ranks beyond a temporarily reduced max_mds."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - A crafted MDSMap arrives in CEPH_MSG_MDS_MAP over the Ceph messenger TCP session from a monitor or MDS; extra_mon_dispatch() and mds_dispatch() deliver it to ceph_mdsc_handle_mdsmap() on already-mounted CephFS/Rook/Kubernetes clients without a local syscall.\nAC:L - The monitor fully controls each export_targets[] u32; after the first map is stored, a later epoch reaches check_new_map() and set_bit() with an attacker-chosen bit number, overflowing the stack bitmap with no race or special layout.\nPR:N - The attacker is the remote Ceph monitor or MDS peer and needs no Linux UID, capability, or init-namespace root on the victim, matching other Ceph client decode CVEs such as CVE-2026-68159.\nUI:N - Once CephFS is mounted, MDS maps are subscribed and applied automatically in the ceph-msgr worker; a malicious peer can push a new epoch without any further interactive victim action.\nS:U - The stack out-of-bounds write corrupts kernel memory on the Ceph client host only and does not cross a VM, IOMMU, or sandbox security authority.\nC:H - set_bit() with an attacker-chosen rank writes past the fixed stack bitmap in check_new_map(), corrupting adjacent kernel stack contents; this memory-corruption primitive can be leveraged for information disclosure.\nI:H - The overflow is a stack out-of-bounds write of attacker-selected bits at a u32-controlled offset from the targets[] array, enabling control-flow hijack and arbitrary kernel writes.\nA:H - An out-of-range bit index makes set_bit() write off the stack object, causing a KASAN stack-out-of-bounds report or kernel oops/panic that a malicious monitor can repeat with each new map epoch."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ceph/mdsmap.c"],"versions":[{"version":"d517b3983dd3106ca92d6c5d0d09415a4a09481c","lessThan":"3740c88ca9cb2210a8dbdd55ea4cec119fbe86fe","status":"affected","versionType":"git"},{"version":"d517b3983dd3106ca92d6c5d0d09415a4a09481c","lessThan":"8c823bbab3c24e657469a84db96902ba82d4e8bb","status":"affected","versionType":"git"},{"version":"d517b3983dd3106ca92d6c5d0d09415a4a09481c","lessThan":"c4addccd05bacbef2144b4db14853d0308a218ac","status":"affected","versionType":"git"},{"version":"d517b3983dd3106ca92d6c5d0d09415a4a09481c","lessThan":"736adee11af36e407ed902264f8b2fb5cf94b62f","status":"affected","versionType":"git"},{"version":"d517b3983dd3106ca92d6c5d0d09415a4a09481c","lessThan":"4d298880f82c42383b36946bafde7ccf4d804c9b","status":"affected","versionType":"git"},{"version":"d517b3983dd3106ca92d6c5d0d09415a4a09481c","lessThan":"96c3f5fbb0d5386e7111426f047f98cec4586674","status":"affected","versionType":"git"},{"version":"d517b3983dd3106ca92d6c5d0d09415a4a09481c","lessThan":"aedc9053d909508a5f56c3f49f885fc030df4730","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ceph/mdsmap.c"],"versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3740c88ca9cb2210a8dbdd55ea4cec119fbe86fe"},{"url":"https://git.kernel.org/stable/c/8c823bbab3c24e657469a84db96902ba82d4e8bb"},{"url":"https://git.kernel.org/stable/c/c4addccd05bacbef2144b4db14853d0308a218ac"},{"url":"https://git.kernel.org/stable/c/736adee11af36e407ed902264f8b2fb5cf94b62f"},{"url":"https://git.kernel.org/stable/c/4d298880f82c42383b36946bafde7ccf4d804c9b"},{"url":"https://git.kernel.org/stable/c/96c3f5fbb0d5386e7111426f047f98cec4586674"},{"url":"https://git.kernel.org/stable/c/aedc9053d909508a5f56c3f49f885fc030df4730"}],"title":"ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode","x_generator":{"engine":"bippy-1.2.0"}}}}