Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-89650

ceph: bound num_export_targets array for mds info v2/v3
Back to all
CVE

CVE-2026-89650

ceph: bound num_export_targets array for mds info v2/v3

In the Linux kernel, the following vulnerability has been resolved:

ceph: bound numexporttargets array for mds info v2/v3

cephmdsmapdecode() in fs/ceph/mdsmap.c reads numexporttargets from

each per-mds info record and advances the decode cursor by

numexporttargets * sizeof(u32) without first checking that many bytes

remain. The only upper-bound check that catches a runaway cursor

(*p > infoend) is gated on infov >= 4, because info_end is left NULL

for info_v 2 and 3. When the monitor sends an MDS map whose per-mds

info version is 2 or 3 with an oversized numexporttargets, the cursor

moves past the message front buffer and the later export-targets loop

calls the unchecked cephdecode32() on out-of-bounds memory.

A kernel client processes CEPHMSGMDS_MAP from its monitor session

(net/ceph/mon_client.c dispatches it; fs/ceph/super.c routes it to

cephmdschandle_mdsmap(), which sets end to the front buffer bound and

calls cephmdsmapdecode()). A malicious or compromised monitor, or an

on-path attacker on an unsigned/unencrypted messenger session, can

therefore drive an out-of-bounds read in the client kernel; on x86_64

with KASAN it is reported as a slab-out-of-bounds read in

cephmdsmapdecode(). The decoded values land in the internal

info->export_targets[] array, so the consequence is a kernel

out-of-bounds read, not an information leak to the attacker.

Impact: a malicious or compromised Ceph monitor sending an MDS map with

a per-mds info version of 2 or 3 and an oversized numexporttargets

field triggers an out-of-bounds read in the CephFS client kernel.

Add a cephdecodeneed() for the export-targets array before advancing

the cursor, so the bound is enforced for every info_v >= 2, not only

info_v >= 4. This mirrors the count-then-need idiom already used for

mdatapg_pools later in the same function.

Compute the export-targets byte count with size_mul() and reuse that

checked length when advancing the cursor, so the attacker-controlled

numexporttargets multiplication fails closed on overflow rather than

relying on the later kcalloc() guard.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.1
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/0c4bcc3ba7291d383b82ce1c2fe324f69a42da2d, https://git.kernel.org/stable/c/332c444f4dc6fa1e8b8637c9e82d29e97f768656, https://git.kernel.org/stable/c/3bf7dba8dba9a05774b846affec61a3624ddba38, https://git.kernel.org/stable/c/55a06b32438c222765138727d0a8164b103e8f0d, https://git.kernel.org/stable/c/58c2d3e954c13694ef6e820a5e9456461bb9e7df, https://git.kernel.org/stable/c/a3eb169ee297aa99670ba927c659990bd1e453f3, https://git.kernel.org/stable/c/eb3e1a1cb1634c76d59c5a9cb1a026fc69d40911, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89650.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89650, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.1

CVSS Score
0
10

Basic Information

Base CVSS
9.1
EPSS Probability
0.00502%
EPSS Percentile
0.41057%
Introduced Version
d463a43d69f4af85887671d76182437775fd1631,4.7.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
a3eb169ee297aa99670ba927c659990bd1e453f3,5.15.221,6.1.188,6.6.157,6.12.109,6.18.50,7.2.4,6.12.111-1~deb12u1,6.12.111-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading