DEBIAN-CVE-2026-89652
In the Linux kernel, the following vulnerability has been resolved: ceph: bound copied dentry name length in NFS export getname cephgetname() copies the MDS-supplied name into the caller's NAMEMAX-sized buffer with memcpy(name, rinfo->dname, rinfo->dnamelen) and then writes name[rinfo->dnamelen] = 0, without checking dnamelen against NAMEMAX. A malicious or buggy MDS that returns a LOOKUPNAME reply with dnamelen > NAMEMAX overflows the buffer. _getsnapname() copies rde->name / rde->namelen the same unchecked way. Impact: a malicious or compromised Ceph MDS overflows the NAMEMAX name buffer in a client's NFS-export getname path, a slab out-of-bounds write reported by KASAN. Reachable when a CephFS mount is re-exported over NFS. Add cephexportcopyname(), which rejects lengths above NAMEMAX with -ENAMETOOLONG before the copy, and use it in both cephgetname() and _getsnap_name().
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-89652