Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-89655

ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock
Back to all
CVE

CVE-2026-89655

ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock

In the Linux kernel, the following vulnerability has been resolved:

ceph: fix UAF in _kickflushing_caps() on cf entry freed during unlock

listforeachentry() iterates ci->icapflushlist but drops

icephlock to send cap messages.  During the unlock window,

handlecapflushack() can acquire iceph_lock, detach cf entries

with tid <= flushtid from the list, release iceph_lock, and free

them via cephfreecap_flush() outside any lock.  When the original

thread reacquires icephlock and the for-loop macro advances via

cf = listnextentry(cf, ilist), it dereferences cf->ilist.next

on freed memory.

The race timeline:

  _kickflushingcaps()              handlecapflushack()

  -----------------------             -----------------------

  holds icephlock        <---

  iterates to cf (tid=10)

  prepares FLUSH message

  drops icephlock        <---

  _sendcap() ── FLUSH(tid=10)

                              MDS sends FLUSH_ACK(tid=10)

                           --->       acquires icephlock

                                      cf->tid(10) <= flush_tid(10),

                                      detaches cf from icapflush_list

                                      drops icephlock

                                      cephfreecap_flush(cf) <- frees it!

  acquires icephlock     <---

  for-loop advances:

    cf = listnextentry(cf, i_list)

      -- UAF on freed cf->i_list.next

The cf was just sent by kickflushingcaps itself via send_cap().

The MDS may respond with FLUSH_ACK quickly enough that

handlecapflushack() frees cf before kickflushing_caps can

finish the iteration.

Fix by converting to a manual while loop: save the next pointer

under icephlock before dropping it, then use the saved pointer

after reacquiring, so the potentially-freed cf is never accessed again.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/01542430081014d80fc9e70e92d6647432ddb7fc, https://git.kernel.org/stable/c/091137821e1fc88f37e15201abf055c9494ddc61, https://git.kernel.org/stable/c/19f16f04c2b014a7dd214dc1e42557d8530b16f3, https://git.kernel.org/stable/c/23eb34a53a53cb1a6dab1eeee830633207ac158d, https://git.kernel.org/stable/c/2701431aa3cc8b23efe6890182e7b04f5e76fab5, https://git.kernel.org/stable/c/2dba24dcd5050be4b7b119e6f0b01f62203b5d26, https://git.kernel.org/stable/c/7af4c4f01305b0935adf6d4301b1ec407025485d, https://git.kernel.org/stable/c/fe46746087b5b9c5bb2d022df6c7819218494ced, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89655.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89655, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00714%
EPSS Percentile
0.52232%
Introduced Version
e4500b5e35c213e0f97be7cb69328c0877203a79,4.8.0,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
7af4c4f01305b0935adf6d4301b1ec407025485d,5.10.270,5.15.221,6.1.188,6.6.157,6.12.109,6.18.50,7.2.4,6.12.111-1~deb12u1,6.12.111-1,0:6.12.0-207.111.5.1.el10uek,0:6.12.0-207.111.5.1.el9uek

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading