{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89655","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.743Z","datePublished":"2026-09-11T19:45:44.841Z","dateUpdated":"2026-09-14T12:01:49.192Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:01:49.192Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock\n\nlist_for_each_entry() iterates ci->i_cap_flush_list but drops\ni_ceph_lock to send cap messages.  During the unlock window,\nhandle_cap_flush_ack() can acquire i_ceph_lock, detach cf entries\nwith tid <= flush_tid from the list, release i_ceph_lock, and free\nthem via ceph_free_cap_flush() outside any lock.  When the original\nthread reacquires i_ceph_lock and the for-loop macro advances via\ncf = list_next_entry(cf, i_list), it dereferences cf->i_list.next\non freed memory.\n\nThe race timeline:\n\n  __kick_flushing_caps()              handle_cap_flush_ack()\n  -----------------------             -----------------------\n  holds i_ceph_lock        <---\n  iterates to cf (tid=10)\n  prepares FLUSH message\n  drops i_ceph_lock        <---\n  __send_cap() ── FLUSH(tid=10)\n\t                              MDS sends FLUSH_ACK(tid=10)\n                           --->       acquires i_ceph_lock\n                                      cf->tid(10) <= flush_tid(10),\n                                      detaches cf from i_cap_flush_list\n                                      drops i_ceph_lock\n                                      ceph_free_cap_flush(cf) <- frees it!\n  acquires i_ceph_lock     <---\n  for-loop advances:\n    cf = list_next_entry(cf, i_list)\n      -- UAF on freed cf->i_list.next\n\nThe cf was just sent by __kick_flushing_caps itself via __send_cap().\nThe MDS may respond with FLUSH_ACK quickly enough that\nhandle_cap_flush_ack() frees cf before __kick_flushing_caps can\nfinish the iteration.\n\nFix by converting to a manual while loop: save the next pointer\nunder i_ceph_lock before dropping it, then use the saved pointer\nafter reacquiring, so the potentially-freed cf is never accessed again."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - handle_cap_flush_ack() runs in the ceph-msgr kworker on CEPH_MSG_CLIENT_CAPS FLUSH_ACK from the MDS over TCP; a malicious or compromised MDS frees the ceph_cap_flush while __kick_flushing_caps() still holds that pointer after dropping i_ceph_lock to send FLUSH.\nAC:L - The MDS controls both sides of the race: it can induce kicking without s_mutex (reconnect sets CEPH_I_KICK_FLUSH, then delayed ceph_check_caps or revoke-queued writeback) and immediately send FLUSH_ACK for the known flush tid in the unlock window around __send_cap().\nPR:N - The attacker is the remote MDS peer on an already-connected kernel CephFS client and needs no Linux UID, capability, or init-namespace root on the victim, matching other MDS-driven client CVEs such as CVE-2026-89651.\nUI:N - Once CephFS is mounted (standard in Rook/Kubernetes/OpenStack), cap-flush kicking runs from mdsc delayed work and writeback, and FLUSH_ACK is processed automatically in kworker context with no further victim mount or interactive step at exploit time.\nS:U - The use-after-free is of a ceph_cap_flush object in the host kernel heap and stays inside the same kernel security authority; it does not cross a VM, IOMMU, or sandbox boundary.\nC:H - After ceph_free_cap_flush(), __kick_flushing_caps() does list_next_entry() on the freed cf; reclaiming the dedicated ceph_cap_flush slab with attacker-controlled objects yields a fake next pointer and arbitrary kernel read, scored High per UAF guidance.\nI:H - The iterator then treats the sprayed object as a live ceph_cap_flush (tid, caps, is_capsnap, i_list) and continues sending cap state from it, giving a heap-reuse write and control-flow hijack primitive scored High for use-after-free.\nA:H - Dereferencing freed cf->i_list.next oopses or panics the kicker thread even without full exploitation, and a malicious MDS can retrigger the race on every cap flush."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ceph/caps.c"],"versions":[{"version":"e4500b5e35c213e0f97be7cb69328c0877203a79","lessThan":"091137821e1fc88f37e15201abf055c9494ddc61","status":"affected","versionType":"git"},{"version":"e4500b5e35c213e0f97be7cb69328c0877203a79","lessThan":"01542430081014d80fc9e70e92d6647432ddb7fc","status":"affected","versionType":"git"},{"version":"e4500b5e35c213e0f97be7cb69328c0877203a79","lessThan":"23eb34a53a53cb1a6dab1eeee830633207ac158d","status":"affected","versionType":"git"},{"version":"e4500b5e35c213e0f97be7cb69328c0877203a79","lessThan":"19f16f04c2b014a7dd214dc1e42557d8530b16f3","status":"affected","versionType":"git"},{"version":"e4500b5e35c213e0f97be7cb69328c0877203a79","lessThan":"2701431aa3cc8b23efe6890182e7b04f5e76fab5","status":"affected","versionType":"git"},{"version":"e4500b5e35c213e0f97be7cb69328c0877203a79","lessThan":"fe46746087b5b9c5bb2d022df6c7819218494ced","status":"affected","versionType":"git"},{"version":"e4500b5e35c213e0f97be7cb69328c0877203a79","lessThan":"2dba24dcd5050be4b7b119e6f0b01f62203b5d26","status":"affected","versionType":"git"},{"version":"e4500b5e35c213e0f97be7cb69328c0877203a79","lessThan":"7af4c4f01305b0935adf6d4301b1ec407025485d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ceph/caps.c"],"versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/091137821e1fc88f37e15201abf055c9494ddc61"},{"url":"https://git.kernel.org/stable/c/01542430081014d80fc9e70e92d6647432ddb7fc"},{"url":"https://git.kernel.org/stable/c/23eb34a53a53cb1a6dab1eeee830633207ac158d"},{"url":"https://git.kernel.org/stable/c/19f16f04c2b014a7dd214dc1e42557d8530b16f3"},{"url":"https://git.kernel.org/stable/c/2701431aa3cc8b23efe6890182e7b04f5e76fab5"},{"url":"https://git.kernel.org/stable/c/fe46746087b5b9c5bb2d022df6c7819218494ced"},{"url":"https://git.kernel.org/stable/c/2dba24dcd5050be4b7b119e6f0b01f62203b5d26"},{"url":"https://git.kernel.org/stable/c/7af4c4f01305b0935adf6d4301b1ec407025485d"}],"title":"ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock","x_generator":{"engine":"bippy-1.2.0"}}}}