DEBIAN-CVE-2026-89653
In the Linux kernel, the following vulnerability has been resolved: ceph: reject exporttargets ranks >= CEPHMAXMDS in mdsmap decode MDSMap exporttargets entries are monitor controlled. checknewmap() uses each entry as a bit number in a fixed stack bitmap, so a rank outside the protocol namespace can make setbit() write past the end of the array. Reject ranks outside CEPHMAXMDS while decoding the map. Do not validate against possiblemaxrank here because maps may legitimately reference ranks beyond a temporarily reduced maxmds.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-89653