CVE-2026-89656
- EPSS 0.46%
- Veröffentlicht 11.09.2026 19:45:45
- Zuletzt bearbeitet 14.09.2026 13:19:18
In the Linux kernel, the following vulnerability has been resolved: libceph: reject buckets with mismatched CRUSH ids crush_decode() stores bucket data by array slot, and the mapper later derives the per-bucket workspace index from the decoded buck...
CVE-2026-89654
- EPSS 0.41%
- Veröffentlicht 11.09.2026 19:45:44
- Zuletzt bearbeitet 13.09.2026 07:17:30
In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in check_new_map() on session freed during unlock check_new_map() iterates mdsc->sessions[] and for each active session drops mdsc->mutex to perform per-session opera...
CVE-2026-89655
- EPSS 0.63%
- Veröffentlicht 11.09.2026 19:45:44
- Zuletzt bearbeitet 14.09.2026 13:19:17
In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock list_for_each_entry() iterates ci->i_cap_flush_list but drops i_ceph_lock to send cap messages. During the ...
CVE-2026-89653
- EPSS 0.46%
- Veröffentlicht 11.09.2026 19:45:43
- Zuletzt bearbeitet 14.09.2026 13:19:17
In the Linux kernel, the following vulnerability has been resolved: ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode MDSMap export_targets entries are monitor controlled. check_new_map() uses each entry as a bit number in a fixed ...
CVE-2026-89652
- EPSS 0.46%
- Veröffentlicht 11.09.2026 19:45:42
- Zuletzt bearbeitet 14.09.2026 13:19:17
In the Linux kernel, the following vulnerability has been resolved: ceph: bound copied dentry name length in NFS export get_name ceph_get_name() copies the MDS-supplied name into the caller's NAME_MAX-sized buffer with memcpy(name, rinfo->dname, ri...
CVE-2026-89651
- EPSS 0.63%
- Veröffentlicht 11.09.2026 19:45:41
- Zuletzt bearbeitet 13.09.2026 07:17:30
In the Linux kernel, the following vulnerability has been resolved: ceph: bound MDSCapAuth path and fs_name decode in handle_session() handle_session() decodes the MDSCapAuth records carried by a CEPH_SESSION_OPEN message (msg_version >= 6). For ea...
CVE-2026-89649
- EPSS 0.6%
- Veröffentlicht 11.09.2026 19:45:40
- Zuletzt bearbeitet 14.09.2026 13:19:17
In the Linux kernel, the following vulnerability has been resolved: ceph: bound xattr value length in __build_xattrs() __build_xattrs() decodes the MDS-supplied xattr blob one attribute at a time. For each attribute it reads a 32-bit name length, a...
CVE-2026-89650
- EPSS 0.46%
- Veröffentlicht 11.09.2026 19:45:40
- Zuletzt bearbeitet 14.09.2026 13:19:17
In the Linux kernel, the following vulnerability has been resolved: ceph: bound num_export_targets array for mds info v2/v3 ceph_mdsmap_decode() in fs/ceph/mdsmap.c reads num_export_targets from each per-mds info record and advances the decode curs...
CVE-2026-89648
- EPSS 0.61%
- Veröffentlicht 11.09.2026 19:45:39
- Zuletzt bearbeitet 13.09.2026 07:17:29
In the Linux kernel, the following vulnerability has been resolved: ceph: cap delegated inode count in ceph_parse_deleg_inos() ceph_parse_deleg_inos() decodes interval sets of delegated inode numbers from an MDS create-with-delegation reply. For ea...
CVE-2026-89647
- EPSS 0.63%
- Veröffentlicht 11.09.2026 19:45:38
- Zuletzt bearbeitet 13.09.2026 07:17:29
In the Linux kernel, the following vulnerability has been resolved: ceph: do not repeat ceph_trim_dentries() if no progress possible ceph_cap_reclaim_work() re-queues itself for as long as ceph_trim_dentries() returns -EAGAIN, which happens wheneve...