Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-80528

ceph: avoid fs reclaim while using current->journal_info
Back to all
CVE

CVE-2026-80528

ceph: avoid fs reclaim while using current->journal_info

In the Linux kernel, the following vulnerability has been resolved:

ceph: avoid fs reclaim while using current->journal_info

handle_reply() stores a cephmdsrequest pointer in

current->journal_info while filling the inode and dentry cache from

an MDS reply.

An allocation in this section can enter direct reclaim and prune

dentries from another filesystem.  If this dirties an ext4 inode, ext4

starts a JBD2 transaction.  JBD2 interprets the Ceph request in

current->journal_info as a journal handle and dereferences the

request's r_tid as h_transaction, causing a kernel crash, e.g.:

 Unable to handle kernel paging request at virtual address 00000000077b4818

 [...]

 Internal error: Oops: 0000000096000004 [#1]  SMP

 Modules linked in:

 CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G        W           6.18.38-i3 #1113 NONE

 [...]

 Workqueue: ceph-msgr cephconworkfn

 pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)

 pc : jbd2_journalstart+0x2c/0x208

 lr : _ext4journalstartsb+0x100/0x178

 [...]

 Call trace:

  jbd2_journalstart+0x2c/0x208 (P)

  _ext4journalstartsb+0x100/0x178

  ext4dirtyinode+0x3c/0x90

  _markinode_dirty+0x58/0x400

  iput.part.0+0x2b0/0x370

  iput+0x18/0x30

  dentryunlinkinode+0xc0/0x158

  _dentrykill+0x80/0x250

  shrinkdentrylist+0x90/0x130

  prunedcachesb+0x60/0x98

  supercachescan+0xe8/0x190

  doshrinkslab+0x174/0x388

  shrink_slab+0xd8/0x4c0

  shrink_node+0x31c/0x908

  dotrytofreepages+0xd0/0x508

  trytofree_pages+0x11c/0x238

  _allocfrozenpagesnoprof+0x4d0/0xdd0

  _folioalloc_noprof+0x18/0x70

  _filemapget_folio+0x248/0x440

  cephreaddirprepopulate+0x570/0x9e8

  mds_dispatch+0x1424/0x1ba0

  cephconprocess_message+0x74/0xa0

  cephconv1tryread+0x3a0/0x1510

  cephconworkfn+0x260/0x460

Enter a scoped NOFS allocation context and leave it after clearing

journal_info.  This prevents filesystem reclaim from recursing into

another filesystem while the field contains Ceph-private data.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/00c12f57a87f537fa8779258fb3a03003a99963e, https://git.kernel.org/stable/c/47b745747b3aa39064724a642884f9df924ddf20, https://git.kernel.org/stable/c/4dbb2c02558e71f93510a6461d7e798b67426b49, https://git.kernel.org/stable/c/5b602344a49e039e792ce5a8923bcc61412ee134, https://git.kernel.org/stable/c/79d95b43ca090426399651ed580dd9bf2db36ab8, https://git.kernel.org/stable/c/b6a0989613072499633e761a1536428a466de7d3, https://git.kernel.org/stable/c/c8a21660c3b90864c391164eea5622e7b5b2897c, https://git.kernel.org/stable/c/ca5fa2380dd90a0adb01580fa6225025351a90f6, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80528.json, https://nvd.nist.gov/vuln/detail/CVE-2026-80528, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00514%
EPSS Percentile
0.41948%
Introduced Version
315f24088048a51eed341c53be66ea477a3c7d16,4.6.0,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
5b602344a49e039e792ce5a8923bcc61412ee134,5.10.266,5.15.217,6.1.184,6.6.153,6.12.105,6.18.46,7.1.10,6.1.187-1,6.12.107-1~deb12u1,6.12.105-1,6.8.0-1036.39,0:6.12.0-207.111.5.1.el10uek,0:5.15.0-325.220.5.el8uek,0:5.15.0-324.217.5.2.el8uek,0:6.12.0-207.111.5.1.el9uek,0:5.15.0-325.220.5.el9uek,0:5.15.0-324.217.5.2.el9uek,1:6.1.186-228.374.amzn2023,1:1.0-0.amzn2023,1:6.18.48-107.148.amzn2023,0:5.10.268-266.1092.amzn2,0:1.0-0.amzn2,0:5.15.220-153.252.amzn2

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading