DEBIAN-CVE-2026-89654
In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in checknewmap() on session freed during unlock checknewmap() iterates mdsc->sessions[] and for each active session drops mdsc->mutex to perform per-session operations. The forced-close path (rank removed from map) correctly takes a reference on s via cephgetmdssession() before releasing mdsc->mutex, but three other paths do not: Path A (address changed): mutexunlock → mutexlock(&s->smutex) Path B (reconnect): mutexunlock → sendmdsreconnect(mdsc, s) Path C (active transition): mutexunlock → mutexlock(&s->smutex) Without the extra reference, another thread can acquire mdsc->mutex during the unlock window, call _unregistersession() which drops the last reference on s, and free it. The original thread then accesses freed memory via s->smutex. Fix by adding cephgetmdssession(s) before each mutexunlock and cephputmdssession(s) after the corresponding mutexlock, matching the pattern already used in the forced-close path. Race timeline (Path A): Thread A (checknewmap) Thread B (another map update holds mdsc->mutex or session teardown) -------------------------- -------------------------- s = mdsc->sessions[i] (refcount == 1, held only by sessions[] array) mutexunlock(&mdsc->mutex) ---> acquires mdsc->mutex _unregistersession(mdsc, s) sessions[i] = NULL cephputmdssession(s) refcount: 1 -> 0 kfree(s) <--- freed! mutexlock(&s->smutex) UAF on freed s->smutex
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-89654