Description
In the Linux kernel, the following vulnerability has been resolved:

libceph: reject buckets with mismatched CRUSH ids

crush_decode() stores bucket data by array slot, and the mapper later
derives the per-bucket workspace index from the decoded bucket id. A
malformed map can therefore make one bucket reuse another bucket's
workspace by encoding an id different from -1 - slot.

For uniform buckets, the second replica selection expands the source
bucket's permutation into that aliased workspace buffer. If the source
bucket is larger than the aliased bucket, the write runs past the smaller
permutation array and can escape the kvmalloc'd CRUSH workspace. KASAN
reports a slab OOB write of 4 bytes in bucket_perm_choose().

Reject buckets whose encoded id does not match their array slot. Valid
CRUSH maps already use the canonical negative id corresponding to the
bucket slot, so this restores the invariant expected by
work->work[-1 - in->id] without changing valid map behavior.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Apply Patch
AI Analysis

Impact

A malformed CRUSH map in the Linux kernel causes the bucket decoder to store bucket data in a bucket's workspace buffer based on an encoded bucket id that does not match its array slot. The later reuse of that workspace by the mapper results in a 4‑byte out‑of‑bounds write within the kernel’s kvmalloc‑allocated CRUSH structures, leading to kernel memory corruption.

Affected Systems

The vulnerability affects the Linux kernel, specifically any distribution or build that includes the libceph subsystem and has not yet applied the fixes contained in the referenced commits. No precise version range is listed, so all current kernels incorporating libceph remain potentially exposed until the patch is deployed.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.8, indicating a critical severity level. The EPSS score is less than 1 %, suggesting a low current likelihood of exploitation, and it is not listed in the CISA KEV catalog. The attack vector likely requires an attacker to supply a malformed CRUSH map to a Ceph cluster, such as by modifying cluster configuration or a Ceph client with map editing permissions. The out‑of‑bounds write in bucket_perm_choose() can corrupt kernel memory, which could lead to a crash or, if an attacker can supply executable code, potentially arbitrary execution with kernel privileges. These consequences are inferred from typical kernel memory corruption outcomes.

Generated by OpenCVE AI on September 15, 2026 at 21:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that incorporates the libceph bucket‑id validation fix.
  • Verify that all Ceph maps use the canonical negative bucket IDs expected by the kernel; reject any maps that encode IDs inconsistent with their array slots.
  • Restrict privileges for modifying Ceph maps to trusted administrators to reduce the chance of malicious malformed maps entering the cluster.

Generated by OpenCVE AI on September 15, 2026 at 21:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Important


Sat, 12 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: libceph: reject buckets with mismatched CRUSH ids crush_decode() stores bucket data by array slot, and the mapper later derives the per-bucket workspace index from the decoded bucket id. A malformed map can therefore make one bucket reuse another bucket's workspace by encoding an id different from -1 - slot. For uniform buckets, the second replica selection expands the source bucket's permutation into that aliased workspace buffer. If the source bucket is larger than the aliased bucket, the write runs past the smaller permutation array and can escape the kvmalloc'd CRUSH workspace. KASAN reports a slab OOB write of 4 bytes in bucket_perm_choose(). Reject buckets whose encoded id does not match their array slot. Valid CRUSH maps already use the canonical negative id corresponding to the bucket slot, so this restores the invariant expected by work->work[-1 - in->id] without changing valid map behavior.
Title libceph: reject buckets with mismatched CRUSH ids
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:01:50.256Z

Reserved: 2026-09-11T19:38:34.743Z

Link: CVE-2026-89656

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:51.813

Modified: 2026-09-14T13:19:18.080

Link: CVE-2026-89656

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:45:45Z

Links: CVE-2026-89656 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:30:16Z

Weaknesses