CVE-2026-89655
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix UAF in _kickflushing_caps() on cf entry freed during unlock
listforeachentry() iterates ci->icapflushlist but drops
icephlock to send cap messages. During the unlock window,
handlecapflushack() can acquire iceph_lock, detach cf entries
with tid <= flushtid from the list, release iceph_lock, and free
them via cephfreecap_flush() outside any lock. When the original
thread reacquires icephlock and the for-loop macro advances via
cf = listnextentry(cf, ilist), it dereferences cf->ilist.next
on freed memory.
The race timeline:
_kickflushingcaps() handlecapflushack()
----------------------- -----------------------
holds icephlock <---
iterates to cf (tid=10)
prepares FLUSH message
drops icephlock <---
_sendcap() ── FLUSH(tid=10)
MDS sends FLUSH_ACK(tid=10)
---> acquires icephlock
cf->tid(10) <= flush_tid(10),
detaches cf from icapflush_list
drops icephlock
cephfreecap_flush(cf) <- frees it!
acquires icephlock <---
for-loop advances:
cf = listnextentry(cf, i_list)
-- UAF on freed cf->i_list.next
The cf was just sent by kickflushingcaps itself via send_cap().
The MDS may respond with FLUSH_ACK quickly enough that
handlecapflushack() frees cf before kickflushing_caps can
finish the iteration.
Fix by converting to a manual while loop: save the next pointer
under icephlock before dropping it, then use the saved pointer
after reacquiring, so the potentially-freed cf is never accessed again.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/01542430081014d80fc9e70e92d6647432ddb7fc, https://git.kernel.org/stable/c/091137821e1fc88f37e15201abf055c9494ddc61, https://git.kernel.org/stable/c/19f16f04c2b014a7dd214dc1e42557d8530b16f3, https://git.kernel.org/stable/c/23eb34a53a53cb1a6dab1eeee830633207ac158d, https://git.kernel.org/stable/c/2701431aa3cc8b23efe6890182e7b04f5e76fab5, https://git.kernel.org/stable/c/2dba24dcd5050be4b7b119e6f0b01f62203b5d26, https://git.kernel.org/stable/c/7af4c4f01305b0935adf6d4301b1ec407025485d, https://git.kernel.org/stable/c/fe46746087b5b9c5bb2d022df6c7819218494ced, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89655.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89655, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git