{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89657","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.743Z","datePublished":"2026-09-11T19:45:46.118Z","dateUpdated":"2026-09-14T12:01:51.323Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:01:51.323Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: validate OSD extent maps before cursor advance\n\nnet/ceph/osd_client.c:osd_sparse_read() validates that the sparse-read\ndata length matches the summed extent lengths, but it does not validate\nthat each OSD-supplied extent is monotonic and lies inside the original\nrequest range. A malformed authenticated OSD reply can advertise a\nfar-forward nonzero extent offset with a matching data length and make\nthe client advance the message-data cursor beyond the request buffer.\nThis reaches the BUG_ON(!*length) assertion in ceph_msg_data_next() from\nthe client receive path.\n\nImpact: A malicious or compromised authenticated Ceph OSD peer can crash\na kernel Ceph client via a malformed sparse-read reply.\n\nReject sparse extent maps that overflow, move backwards, overlap, or\nextend outside the original sparse-read request before advancing the\ncursor.\n\n[ idryomov: perform sparse_extent_map_valid() check a bit earlier,\n  in CEPH_SPARSE_READ_DATA_LEN instead of CEPH_SPARSE_READ_DATA_PRE\n  state ]"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The malformed sparse-read extent map is consumed in osd_sparse_read() on the Ceph messenger TCP receive path (messenger_v1/v2) when a kernel CephFS client handles an MOSDOpReply from a remote OSD; no local syscall or ioctl is required to parse the reply.\nAC:L - A malicious OSD fully controls the sparse extent offsets and lengths and can advertise a far-forward nonzero extent with a matching data length, deterministically advancing the message-data cursor past the request buffer into BUG_ON(!*length) in ceph_msg_data_next() with no race or special memory layout.\nPR:N - The attacker acts as a remote Ceph OSD peer on a compromised or attacker-controlled cluster and needs no account, capabilities, or user-namespace privileges on the victim Linux host; any kernel CephFS client connected to that cluster is exposed.\nUI:N - Once CephFS is mounted with fscrypt-encrypted files or the sparseread option, netfs/buffered reads and encrypted RMW writes issue CEPH_OSD_OP_SPARSE_READ as normal I/O; the OSD can crash the client on the next such reply without further victim action at exploit time.\nS:U - The BUG_ON panic occurs in the kernel Ceph client's receive path on the same host and does not cross a VM, IOMMU, or sandbox boundary to another security authority.\nC:N - ceph_msg_data_next() hits BUG_ON(!*length) and related cursor assertions when the buffer is exhausted, before any out-of-bounds page access; there is no use-after-free, OOB read, or other information-disclosure primitive.\nI:N - Cursor over-advance is stopped by BUG_ON assertions rather than writing past the allocated request pages; hole-zeroing via zero_user_segment stays inside the destination buffer until the panic, so there is no arbitrary kernel write or control-flow hijack.\nA:H - BUG_ON(!*length) in ceph_msg_data_next() on the client receive path causes a kernel oops or panic, fully denying availability of the affected Ceph client host until reboot."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/ceph/osd_client.c"],"versions":[{"version":"f628d799972799023d32c2542bb2639eb8c4f84e","lessThan":"94ae5145c520618802b0a24c047dcd5f05835db8","status":"affected","versionType":"git"},{"version":"f628d799972799023d32c2542bb2639eb8c4f84e","lessThan":"058ffa81f9440c5b4714685611cf697fd3739ec9","status":"affected","versionType":"git"},{"version":"f628d799972799023d32c2542bb2639eb8c4f84e","lessThan":"2571b35883268a266554e80d368e67fdfea7fb9d","status":"affected","versionType":"git"},{"version":"f628d799972799023d32c2542bb2639eb8c4f84e","lessThan":"201db408872ca12cf09e36bf0f560138c3dcfa1c","status":"affected","versionType":"git"},{"version":"f628d799972799023d32c2542bb2639eb8c4f84e","lessThan":"9ec08b7499a62c6d4afa93d36ab47a43fcad57d1","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/ceph/osd_client.c"],"versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/94ae5145c520618802b0a24c047dcd5f05835db8"},{"url":"https://git.kernel.org/stable/c/058ffa81f9440c5b4714685611cf697fd3739ec9"},{"url":"https://git.kernel.org/stable/c/2571b35883268a266554e80d368e67fdfea7fb9d"},{"url":"https://git.kernel.org/stable/c/201db408872ca12cf09e36bf0f560138c3dcfa1c"},{"url":"https://git.kernel.org/stable/c/9ec08b7499a62c6d4afa93d36ab47a43fcad57d1"}],"title":"libceph: validate OSD extent maps before cursor advance","x_generator":{"engine":"bippy-1.2.0"}}}}