Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-89650

In the Linux kernel, the following vulnerability has been resolved: ceph: bound num_export_targets array for mds info v2/v3 ceph_mdsmap_decode() in fs/ceph/mdsmap.c reads num_export_targets from eac...
Back to all
CVE

DEBIAN-CVE-2026-89650

In the Linux kernel, the following vulnerability has been resolved: ceph: bound num_export_targets array for mds info v2/v3 ceph_mdsmap_decode() in fs/ceph/mdsmap.c reads num_export_targets from eac...

In the Linux kernel, the following vulnerability has been resolved:  ceph: bound numexporttargets array for mds info v2/v3  cephmdsmapdecode() in fs/ceph/mdsmap.c reads numexporttargets from each per-mds info record and advances the decode cursor by numexporttargets  sizeof(u32) without first checking that many bytes remain. The only upper-bound check that catches a runaway cursor (p > infoend) is gated on infov >= 4, because infoend is left NULL for infov 2 and 3. When the monitor sends an MDS map whose per-mds info version is 2 or 3 with an oversized numexporttargets, the cursor moves past the message front buffer and the later export-targets loop calls the unchecked cephdecode32() on out-of-bounds memory.  A kernel client processes CEPHMSGMDSMAP from its monitor session (net/ceph/monclient.c dispatches it; fs/ceph/super.c routes it to cephmdschandlemdsmap(), which sets end to the front buffer bound and calls cephmdsmapdecode()). A malicious or compromised monitor, or an on-path attacker on an unsigned/unencrypted messenger session, can therefore drive an out-of-bounds read in the client kernel; on x8664 with KASAN it is reported as a slab-out-of-bounds read in cephmdsmapdecode(). The decoded values land in the internal info->exporttargets[] array, so the consequence is a kernel out-of-bounds read, not an information leak to the attacker.  Impact: a malicious or compromised Ceph monitor sending an MDS map with a per-mds info version of 2 or 3 and an oversized numexporttargets field triggers an out-of-bounds read in the CephFS client kernel.  Add a cephdecodeneed() for the export-targets array before advancing the cursor, so the bound is enforced for every infov >= 2, not only infov >= 4. This mirrors the count-then-need idiom already used for mdatapgpools later in the same function.  Compute the export-targets byte count with sizemul() and reuse that checked length when advancing the cursor, so the attacker-controlled numexport_targets multiplication fails closed on overflow rather than relying on the later kcalloc() guard.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-89650

Severity

9.1

CVSS Score
0
10

Basic Information

Base CVSS
9.1
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
6.12.111-1,7.2.6-1,6.12.111-1~deb12u1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading