Description
In the Linux kernel, the following vulnerability has been resolved:

ceph: bound xattr value length in __build_xattrs()

__build_xattrs() decodes the MDS-supplied xattr blob one attribute at a
time. For each attribute it reads a 32-bit name length, advances past the
name bytes, reads a 32-bit value length, records the value pointer, and
advances past the value bytes. The two length fields are read with
ceph_decode_32_safe(), but the value bytes themselves are advanced over
with a bare "p += len" and no ceph_decode_need() check that "len" bytes
remain in the blob.

For every attribute except the last, the next iteration's
ceph_decode_32_safe() on the following name length implicitly verifies
that the previous value did not run past the blob end. The final
attribute has no successor, so its decoded value length is never checked
against the blob bounds. A malicious or compromised metadata server can
set the last attribute's value length larger than the bytes actually
present in the blob.

The blob is a dedicated kvmalloc() allocation sized to the wire length
(ceph_buffer_new() in ceph_fill_inode()). __set_xattr() records the
oversized length in xattr->val_len verbatim, and a later getxattr(2) runs
memcpy(value, xattr->val, xattr->val_len) into a user-supplied buffer,
copying bytes past the end of the allocation back to user space.

Impact: a malicious metadata server discloses adjacent kernel heap bytes
to a local user via getxattr(2) on a CephFS file. Add the missing
ceph_decode_need() so an out-of-bounds value length on the final
attribute fails the decode and returns -EIO instead of being stored.
Published: 2026-09-11
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Kernel heap information disclosure via getxattr
Action: Apply patch
AI Analysis

Impact

The vulnerability resides in the Linux kernel’s CephFS implementation, where the function __build_xattrs parses an xattr blob supplied by a Ceph metadata server and inadvertently skips a bounds check for the final attribute’s value length. When the value length reported by the metadata server exceeds the actual data present, a later getxattr(2) call copies beyond the intended allocation, leaking adjacent kernel heap bytes to user space. This flaw manifests as an information disclosure that reveals sensitive memory content without affecting integrity or availability. The weakness aligns with CWE-125: Improper Validation of Array Index or Pointer Arithmetic.

Affected Systems

Affected systems are Linux kernel environments that host CephFS filesystems. The vulnerability is present in any kernel version where the CephFS module implements __build_xattrs without the added bounds check, as identified by the generic CPE for Linux kernels. No specific version or patch level is provided in the CNA data, so all current distributions running CephFS are potentially impacted.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity due to the local user scope and the lack of privilege escalation. Exploitation requires a compromised or malicious Ceph metadata server that can forge an xattr blob for a file on the local host; the attack surface is limited to systems with CephFS enabled. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower likelihood of widespread attacks. However, any local user with access to a CephFS mount can trigger the disclosure by issuing getxattr against a crafted file. The risk level remains high but warrants timely patching to mitigate the potential exposure of kernel memory contents.

Generated by OpenCVE AI on September 15, 2026 at 20:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that incorporates the ceph_decode_need() bounds check in __build_xattrs()
  • Restart affected services or reboot to ensure the patched kernel is active, then verify that CephFS mounts are using the fixed kernel version
  • If an immediate kernel update is not feasible, consider disabling xattr support or unmounting CephFS until the patch can be applied to prevent the information disclosure modality

Generated by OpenCVE AI on September 15, 2026 at 20:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ceph: bound xattr value length in __build_xattrs() __build_xattrs() decodes the MDS-supplied xattr blob one attribute at a time. For each attribute it reads a 32-bit name length, advances past the name bytes, reads a 32-bit value length, records the value pointer, and advances past the value bytes. The two length fields are read with ceph_decode_32_safe(), but the value bytes themselves are advanced over with a bare "p += len" and no ceph_decode_need() check that "len" bytes remain in the blob. For every attribute except the last, the next iteration's ceph_decode_32_safe() on the following name length implicitly verifies that the previous value did not run past the blob end. The final attribute has no successor, so its decoded value length is never checked against the blob bounds. A malicious or compromised metadata server can set the last attribute's value length larger than the bytes actually present in the blob. The blob is a dedicated kvmalloc() allocation sized to the wire length (ceph_buffer_new() in ceph_fill_inode()). __set_xattr() records the oversized length in xattr->val_len verbatim, and a later getxattr(2) runs memcpy(value, xattr->val, xattr->val_len) into a user-supplied buffer, copying bytes past the end of the allocation back to user space. Impact: a malicious metadata server discloses adjacent kernel heap bytes to a local user via getxattr(2) on a CephFS file. Add the missing ceph_decode_need() so an out-of-bounds value length on the final attribute fails the decode and returns -EIO instead of being stored.
Title ceph: bound xattr value length in __build_xattrs()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:44.932Z

Reserved: 2026-09-11T19:38:34.742Z

Link: CVE-2026-89649

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:50.897

Modified: 2026-09-14T13:19:17.230

Link: CVE-2026-89649

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:40Z

Links: CVE-2026-89649 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:00:17Z

Weaknesses