CVE-2026-89657
Received Received - Intake

Memory Corruption in Linux Kernel Ceph Client

Vulnerability report for CVE-2026-89657, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: libceph: validate OSD extent maps before cursor advance net/ceph/osd_client.c:osd_sparse_read() validates that the sparse-read data length matches the summed extent lengths, but it does not validate that each OSD-supplied extent is monotonic and lies inside the original request range. A malformed authenticated OSD reply can advertise a far-forward nonzero extent offset with a matching data length and make the client advance the message-data cursor beyond the request buffer. This reaches the BUG_ON(!*length) assertion in ceph_msg_data_next() from the client receive path. Impact: A malicious or compromised authenticated Ceph OSD peer can crash a kernel Ceph client via a malformed sparse-read reply. Reject sparse extent maps that overflow, move backwards, overlap, or extend outside the original sparse-read request before advancing the cursor. [ idryomov: perform sparse_extent_map_valid() check a bit earlier, in CEPH_SPARSE_READ_DATA_LEN instead of CEPH_SPARSE_READ_DATA_PRE state ]

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the Ceph client's handling of OSD extent maps during sparse reads. The client fails to validate that OSD-supplied extents are monotonic and within the original request range. A malicious OSD peer can send a malformed reply with a far-forward extent offset, causing the client to advance a message-data cursor beyond the buffer and trigger a BUG_ON assertion, leading to a crash.

Detection Guidance

This vulnerability involves malformed Ceph OSD replies crashing kernel Ceph clients. Detection requires monitoring for crashes in Ceph client systems or analyzing network traffic for malformed sparse-read replies. Check kernel logs for BUG_ON assertions in ceph_msg_data_next() and inspect Ceph OSD reply packets for invalid extent maps.

Impact Analysis

If you use a Linux system with Ceph client functionality, this vulnerability could allow an attacker with access to a compromised or malicious Ceph OSD peer to crash your kernel Ceph client. This could disrupt services relying on Ceph storage, potentially causing data unavailability or system instability.

Compliance Impact

This vulnerability primarily causes denial-of-service by crashing kernel Ceph clients, which could disrupt data availability. For compliance standards like GDPR or HIPAA, which require data availability and integrity, such disruptions may lead to violations if critical data becomes inaccessible during an outage.

Mitigation Strategies

Apply the Linux kernel patch that adds validation for OSD extent maps. Update Ceph client systems to a patched kernel version. Ensure all Ceph OSD peers are trusted and authenticated to prevent malicious replies. Monitor for crashes and network anomalies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89657. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart