Impact
The flaw is caused by the ceph_get_name() and __get_snap_name() functions copying a Ceph MDS reply name into a fixed-size NAME_MAX buffer without validating the length. A malicious or buggy MDS that returns a dname_len larger than NAME_MAX triggers a memory overwrite that can corrupt kernel data structures. This classic out-of-bounds buffer overflow (CWE-120) is reachable when a CephFS filesystem is re‑exported over NFS, potentially allowing an attacker to gain kernel privileges or crash the system.
Affected Systems
Linux kernel builds that expose the ceph_get_name() and __get_snap_name() routines before the patch introducing ceph_export_copy_name() are vulnerable. The CVE statement does not list specific kernel versions, but any kernel that includes the unpatched ceph code and allows a CephFS export over NFS is affected.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score of <1% suggests a low but non‑zero probability of exploitation, and the vulnerability is not listed in KEV. The exploitation requires an attacker who can alter or fabricate a Ceph MDS LOOKUPNAME reply, which typically demands either compromising the Ceph MDS or gaining control over the network channel between the MDS and the NFS client. If successful, the overflow allows an out‑of‑bounds write to kernel memory that can lead to privilege escalation or denial of service.
OpenCVE Enrichment
Debian DSA