Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-80528

In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current->journal_info handle_reply() stores a `ceph_mds_request` pointer in `current->journal_i...
Back to all
CVE

DEBIAN-CVE-2026-80528

In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current->journal_info handle_reply() stores a `ceph_mds_request` pointer in `current->journal_i...

In the Linux kernel, the following vulnerability has been resolved:  ceph: avoid fs reclaim while using current->journalinfo  handlereply() stores a cephmdsrequest pointer in current->journal_info while filling the inode and dentry cache from an MDS reply.  An allocation in this section can enter direct reclaim and prune dentries from another filesystem.  If this dirties an ext4 inode, ext4 starts a JBD2 transaction.  JBD2 interprets the Ceph request in current->journal_info as a journal handle and dereferences the request's r_tid as h_transaction, causing a kernel crash, e.g.:   Unable to handle kernel paging request at virtual address 00000000077b4818  [...]  Internal error: Oops: 0000000096000004 [#1]  SMP  Modules linked in:  CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G        W           6.18.38-i3 #1113 NONE  [...]  Workqueue: ceph-msgr cephconworkfn  pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)  pc : jbd2journalstart+0x2c/0x208  lr : ext4journalstartsb+0x100/0x178  [...]  Call trace:   jbd2journalstart+0x2c/0x208 (P)   ext4journalstartsb+0x100/0x178   ext4dirtyinode+0x3c/0x90   markinodedirty+0x58/0x400   iput.part.0+0x2b0/0x370   iput+0x18/0x30   dentryunlinkinode+0xc0/0x158   dentrykill+0x80/0x250   shrinkdentrylist+0x90/0x130   prunedcachesb+0x60/0x98   supercachescan+0xe8/0x190   doshrinkslab+0x174/0x388   shrinkslab+0xd8/0x4c0   shrinknode+0x31c/0x908   dotrytofreepages+0xd0/0x508   trytofreepages+0x11c/0x238   allocfrozenpagesnoprof+0x4d0/0xdd0   folioallocnoprof+0x18/0x70   filemapgetfolio+0x248/0x440   cephreaddirprepopulate+0x570/0x9e8   mdsdispatch+0x1424/0x1ba0   cephconprocessmessage+0x74/0xa0   cephconv1tryread+0x3a0/0x1510   cephcon_workfn+0x260/0x460  Enter a scoped NOFS allocation context and leave it after clearing journal_info.  This prevents filesystem reclaim from recursing into another filesystem while the field contains Ceph-private data.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-80528

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
6.1.187-1,6.12.105-1,7.1.10-1,6.12.107-1~deb12u1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading