9.1

CVE-2026-89650

ceph: bound num_export_targets array for mds info v2/v3

In the Linux kernel, the following vulnerability has been resolved:

ceph: bound num_export_targets array for mds info v2/v3

ceph_mdsmap_decode() in fs/ceph/mdsmap.c reads num_export_targets from
each per-mds info record and advances the decode cursor by
num_export_targets * sizeof(u32) without first checking that many bytes
remain. The only upper-bound check that catches a runaway cursor
(*p > info_end) is gated on info_v >= 4, because info_end is left NULL
for info_v 2 and 3. When the monitor sends an MDS map whose per-mds
info version is 2 or 3 with an oversized num_export_targets, the cursor
moves past the message front buffer and the later export-targets loop
calls the unchecked ceph_decode_32() on out-of-bounds memory.

A kernel client processes CEPH_MSG_MDS_MAP from its monitor session
(net/ceph/mon_client.c dispatches it; fs/ceph/super.c routes it to
ceph_mdsc_handle_mdsmap(), which sets end to the front buffer bound and
calls ceph_mdsmap_decode()). A malicious or compromised monitor, or an
on-path attacker on an unsigned/unencrypted messenger session, can
therefore drive an out-of-bounds read in the client kernel; on x86_64
with KASAN it is reported as a slab-out-of-bounds read in
ceph_mdsmap_decode(). The decoded values land in the internal
info->export_targets[] array, so the consequence is a kernel
out-of-bounds read, not an information leak to the attacker.

Impact: a malicious or compromised Ceph monitor sending an MDS map with
a per-mds info version of 2 or 3 and an oversized num_export_targets
field triggers an out-of-bounds read in the CephFS client kernel.

Add a ceph_decode_need() for the export-targets array before advancing
the cursor, so the bound is enforced for every info_v >= 2, not only
info_v >= 4. This mirrors the count-then-need idiom already used for
m_data_pg_pools later in the same function.

Compute the export-targets byte count with size_mul() and reuse that
checked length when advancing the cursor, so the attacker-controlled
num_export_targets multiplication fails closed on overflow rather than
relying on the later kcalloc() guard.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version d463a43d69f4af85887671d76182437775fd1631
Version < 0c4bcc3ba7291d383b82ce1c2fe324f69a42da2d
Status affected
Version d463a43d69f4af85887671d76182437775fd1631
Version < 55a06b32438c222765138727d0a8164b103e8f0d
Status affected
Version d463a43d69f4af85887671d76182437775fd1631
Version < eb3e1a1cb1634c76d59c5a9cb1a026fc69d40911
Status affected
Version d463a43d69f4af85887671d76182437775fd1631
Version < 3bf7dba8dba9a05774b846affec61a3624ddba38
Status affected
Version d463a43d69f4af85887671d76182437775fd1631
Version < 58c2d3e954c13694ef6e820a5e9456461bb9e7df
Status affected
Version d463a43d69f4af85887671d76182437775fd1631
Version < 332c444f4dc6fa1e8b8637c9e82d29e97f768656
Status affected
Version d463a43d69f4af85887671d76182437775fd1631
Version < a3eb169ee297aa99670ba927c659990bd1e453f3
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.7
Status affected
Version 0
Version < 4.7
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.388
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3bf7dba8dba9a05774b846affec61a3624ddba38
https://git.kernel.org/stable/c/58c2d3e954c13694ef6e820a5e9456461bb9e7df
https://git.kernel.org/stable/c/332c444f4dc6fa1e8b8637c9e82d29e97f768656
https://git.kernel.org/stable/c/a3eb169ee297aa99670ba927c659990bd1e453f3
https://git.kernel.org/stable/c/0c4bcc3ba7291d383b82ce1c2fe324f69a42da2d
https://git.kernel.org/stable/c/55a06b32438c222765138727d0a8164b103e8f0d
https://git.kernel.org/stable/c/eb3e1a1cb1634c76d59c5a9cb1a026fc69d40911