Impact
The Linux kernel CephFS client contains an out-of-bounds read flaw. When a monitor sends an MDS map with a per-MDS info version of 2 or 3 that specifies an oversized num_export_targets field, the decode cursor in fs/ceph/mdsmap.c moves beyond the message buffer because no length is checked before advancing. The subsequent loop that reads export targets calls an unchecked ceph_decode_32 on memory beyond the buffer, and the data is written into the internal info->export_targets[] array. The read is not driven by attacker‑controlled data and therefore does not leak information, but it does cause a kernel out-of-bounds read that can lead to a fault or corrupted internal state.
Affected Systems
All Linux kernel implementations that include CephFS client code are affected. The bug is present in any kernel version where ceph_mdsmap_decode() reads num_export_targets without bounding checks in fs/ceph/mdsmap.c. Users MDS map messages from a monitor using per-MDS info version 2 or 3 are impacted.
Risk and Exploitability
The CVSS score of 9.1 indicates high severity. However, the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a very low probability of exploitation in the wild. An attacker must control or compromise a Ceph monitor or gain access to an unsigned messenger session to trigger the flaw. The weakness causes only an out-of-bounds read in the kernel, which can lead to a fault or kernel crash but does not leak information or provide direct control. Because exploitation requires a highly specific attack surface, the overall risk to typical deployments is low, although the affected kernel component remains vulnerable.
OpenCVE Enrichment
Debian DSA