CVE-2026-89654
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix UAF in checknewmap() on session freed during unlock
checknewmap() iterates mdsc->sessions[] and for each active session
drops mdsc->mutex to perform per-session operations. The forced-close
path (rank removed from map) correctly takes a reference on s via
cephgetmds_session() before releasing mdsc->mutex, but three other
paths do not:
Path A (address changed): mutexunlock → mutexlock(&s->s_mutex)
Path B (reconnect): mutexunlock → sendmds_reconnect(mdsc, s)
Path C (active transition): mutexunlock → mutexlock(&s->s_mutex)
Without the extra reference, another thread can acquire mdsc->mutex
during the unlock window, call _unregistersession() which drops the
last reference on s, and free it. The original thread then accesses
freed memory via s->s_mutex.
Fix by adding cephgetmdssession(s) before each mutexunlock and
cephputmdssession(s) after the corresponding mutexlock, matching
the pattern already used in the forced-close path.
Race timeline (Path A):
Thread A (checknewmap) Thread B (another map update
holds mdsc->mutex or session teardown)
-------------------------- --------------------------
s = mdsc->sessions[i]
(refcount == 1, held only by
sessions[] array)
mutex_unlock(&mdsc->mutex)
---> acquires mdsc->mutex
_unregistersession(mdsc, s)
sessions[i] = NULL
cephputmds_session(s)
refcount: 1 -> 0
kfree(s) <--- freed!
mutexlock(&s->smutex)
UAF on freed s->s_mutex
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/21d5be092d947f8d83f76f7ebf3989e7e9230a98, https://git.kernel.org/stable/c/ee611a7509554c4ca1f54f6aefe592fb1df7ea70, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89654.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89654, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git