Impact
The vulnerability resides in the Linux kernel’s Ceph integration, where the handle_session() routine decodes MDSCapAuth records without performing bounds checks on the path and fs_name byte strings. Because the record lengths are decoded but not validated, a malicious or compromised Master Data Server can provide values that exceed the remaining bytes in the message front buffer, causing ceph_decode_copy() to read past the end of the dedicated allocation. This out‑of‑bounds read can crash the clients during session setup, resulting in a denial of service for the affected host.
Affected Systems
All Linux kernels that include the ceph handle_session() code path are potentially impacted. No specific kernel versions are listed in the advisory, so any kernel containing this logic remains at risk until patched.
Risk and Exploitability
The likely attack vector is a malicious MDS that sends a crafted CEPH_SESSION_OPEN message to a client kernel. The CVSS score of 9.8 indicates a high severity, yet the EPSS score is reported as < 1 %, implying a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. If exploited, the attacker would induce a kernel crash (denial of service) on the targeted client host; the effect is contained to that host and does not provide direct control over memory or privilege escalation.
OpenCVE Enrichment
Debian DSA