Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-89654

In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in check_new_map() on session freed during unlock check_new_map() iterates mdsc->sessions[] and for each active sess...
Back to all
CVE

DEBIAN-CVE-2026-89654

In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in check_new_map() on session freed during unlock check_new_map() iterates mdsc->sessions[] and for each active sess...

In the Linux kernel, the following vulnerability has been resolved:  ceph: fix UAF in checknewmap() on session freed during unlock  checknewmap() iterates mdsc->sessions[] and for each active session drops mdsc->mutex to perform per-session operations.  The forced-close path (rank removed from map) correctly takes a reference on s via cephgetmdssession() before releasing mdsc->mutex, but three other paths do not:    Path A (address changed):  mutexunlock → mutexlock(&s->smutex)   Path B (reconnect):        mutexunlock → sendmdsreconnect(mdsc, s)   Path C (active transition): mutexunlock → mutexlock(&s->smutex)  Without the extra reference, another thread can acquire mdsc->mutex during the unlock window, call _unregistersession() which drops the last reference on s, and free it.  The original thread then accesses freed memory via s->smutex.  Fix by adding cephgetmdssession(s) before each mutexunlock and cephputmdssession(s) after the corresponding mutexlock, matching the pattern already used in the forced-close path.  Race timeline (Path A):    Thread A (checknewmap)             Thread B (another map update     holds mdsc->mutex                      or session teardown)   --------------------------           --------------------------   s = mdsc->sessions[i]   (refcount == 1, held only by    sessions[] array)    mutexunlock(&mdsc->mutex)                                --->    acquires mdsc->mutex                                        _unregistersession(mdsc, s)                                          sessions[i] = NULL                                          cephputmdssession(s)                                            refcount: 1 -> 0                                            kfree(s)  <--- freed!    mutexlock(&s->smutex)   UAF on freed s->smutex

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-89654

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
7.2.6-1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading