Impact
The vulnerability is an out‑of‑bounds write in the Linux kernel’s Ceph subsystem, classified as CWE‑787. When a Ceph MDSMap contains an export_targets entry whose rank value is greater than or equal to CEPH_MAX_MDS, the code interprets that rank as a bit index in a fixed bitmap. The subsequent set_bit() operation writes past the array’s bounds, corrupting adjacent kernel memory decoding phase, which is part of normal Ceph cluster operation. The corruption can lead to crashes, data loss, or loss of integrity in kernel data structures.
Affected Systems
All Linux kernels that include the Ceph subsystem and have not applied the newest update incorporating the fix that rejects export_targets ranks outside the CEPH_MAX_MDS range are affected. The issue is present whenever a node processes a Ceph MDSMap, so any system running a Ceph Metadata Server or a client that may receive such maps is potentially at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity with high impact on confidentiality, integrity and availability. The EPSS score of less than 1% suggests that exploitation remains rare to date. There is no public information about exploitation of this vulnerability. Based on the description, the likely attack vector is remote network: an attacker can send a crafted MDSMap containing an out‑of‑bounds rank to a victim node, causing the overflow during map decoding. Successful exploitation requires the ability to target, but does not require local or privileged access.
OpenCVE Enrichment
Debian DSA