Impact
The Linux kernel’s Ceph client module contains a flaw in ceph_parse_deleg_inos() that decodes delegated‑inode intervals sent by a Ceph Metadata Server. The function reads a 64‑bit length field without validating its value and then loops over that length inserting entries into an xarray. Because the length is fully controllable by the sender, a malicious MDS can cause the client to perform an unbounded loop or grow its delegated‑inode data structure without limit, leading to excessive CPU and memory consumption and a denial of service for the client.
Affected Systems
Any Linux kernel that includes the unpatched ceph_parse_deleg_inos() implementation is affected. This encompasses all kernel releases shipping with the Ceph client modules prior to the commit that introduces the per‑session counter cap and aggregate interval length enforcement. All setups where a Ceph client talks directly to a Metadata Server over the network run the risk until the kernel is updated.
Risk and Exploitability
The CVSS score of 7.5 classifies this as a high‑severity resource exhaustion vulnerability. The EPSS score of less than 1 % indicates that exploitation is currently rare but possible. The vulnerability is not listed in the CISA KEV catalog. Attackers need control of or the ability to subvert a Ceph Metadata Server to send crafted delegation replies; by providing one oversized interval, many intervals, duplicate ranges, or repeated replies, an attacker can force the client to spin through an unbounded loop or grow its delegated‑inode xarray, exhausting CPU and memory and denying service.
OpenCVE Enrichment