Impact
The vulnerability resides in the Linux kernel’s CephFS implementation, where the function __build_xattrs parses an xattr blob supplied by a Ceph metadata server and inadvertently skips a bounds check for the final attribute’s value length. When the value length reported by the metadata server exceeds the actual data present, a later getxattr(2) call copies beyond the intended allocation, leaking adjacent kernel heap bytes to user space. This flaw manifests as an information disclosure that reveals sensitive memory content without affecting integrity or availability. The weakness aligns with CWE-125: Improper Validation of Array Index or Pointer Arithmetic.
Affected Systems
Affected systems are Linux kernel environments that host CephFS filesystems. The vulnerability is present in any kernel version where the CephFS module implements __build_xattrs without the added bounds check, as identified by the generic CPE for Linux kernels. No specific version or patch level is provided in the CNA data, so all current distributions running CephFS are potentially impacted.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity due to the local user scope and the lack of privilege escalation. Exploitation requires a compromised or malicious Ceph metadata server that can forge an xattr blob for a file on the local host; the attack surface is limited to systems with CephFS enabled. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower likelihood of widespread attacks. However, any local user with access to a CephFS mount can trigger the disclosure by issuing getxattr against a crafted file. The risk level remains high but warrants timely patching to mitigate the potential exposure of kernel memory contents.
OpenCVE Enrichment
Debian DSA