Description
In the Linux kernel, the following vulnerability has been resolved:

ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode

MDSMap export_targets entries are monitor controlled. check_new_map()
uses each entry as a bit number in a fixed stack bitmap, so a rank
outside the protocol namespace can make set_bit() write past the end of
the array.

Reject ranks outside CEPH_MAX_MDS while decoding the map. Do not
validate against possible_max_rank here because maps may legitimately
reference ranks beyond a temporarily reduced max_mds.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: kernel memory corruption
Action: Patch
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write in the Linux kernel’s Ceph subsystem, classified as CWE‑787. When a Ceph MDSMap contains an export_targets entry whose rank value is greater than or equal to CEPH_MAX_MDS, the code interprets that rank as a bit index in a fixed bitmap. The subsequent set_bit() operation writes past the array’s bounds, corrupting adjacent kernel memory decoding phase, which is part of normal Ceph cluster operation. The corruption can lead to crashes, data loss, or loss of integrity in kernel data structures.

Affected Systems

All Linux kernels that include the Ceph subsystem and have not applied the newest update incorporating the fix that rejects export_targets ranks outside the CEPH_MAX_MDS range are affected. The issue is present whenever a node processes a Ceph MDSMap, so any system running a Ceph Metadata Server or a client that may receive such maps is potentially at risk.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity with high impact on confidentiality, integrity and availability. The EPSS score of less than 1% suggests that exploitation remains rare to date. There is no public information about exploitation of this vulnerability. Based on the description, the likely attack vector is remote network: an attacker can send a crafted MDSMap containing an out‑of‑bounds rank to a victim node, causing the overflow during map decoding. Successful exploitation requires the ability to target, but does not require local or privileged access.

Generated by OpenCVE AI on September 15, 2026 at 20:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the fix rejecting export_targets ranks >= CEPH_MAX_MDS during MDSMap decoding.
  • If a patch cannot be applied immediately, limit Ceph monitor access so that only trusted nodes can transmit MDSMap data—use firewall rules or TLS authentication to block untrusted traffic.
  • After applying the patch or tightening network restrictions, run a Ceph cluster consistency check and monitor system logs for memory corruption indicators to verify that the vulnerability has been fully mitigated.

Generated by OpenCVE AI on September 15, 2026 at 20:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-788

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-788

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode MDSMap export_targets entries are monitor controlled. check_new_map() uses each entry as a bit number in a fixed stack bitmap, so a rank outside the protocol namespace can make set_bit() write past the end of the array. Reject ranks outside CEPH_MAX_MDS while decoding the map. Do not validate against possible_max_rank here because maps may legitimately reference ranks beyond a temporarily reduced max_mds.
Title ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:48.132Z

Reserved: 2026-09-11T19:38:34.742Z

Link: CVE-2026-89653

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:51.400

Modified: 2026-09-14T13:19:17.697

Link: CVE-2026-89653

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:43Z

Links: CVE-2026-89653 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:00:17Z

Weaknesses