Description
In the Linux kernel, the following vulnerability has been resolved:

ceph: lock mutex in ceph_mds_check_access()

MDS session OPEN handling replaces mdsc->s_cap_auths under
mdsc->mutex, freeing the previous array and its strings.

ceph_mds_check_access() traverses this array without holding the
mutex. A concurrent session reopen can therefore free the array while
it is being inspected, resulting in a use-after-free like this:

Unable to handle kernel paging request at virtual address 003aaad64b2c8bb9
[...]
Internal error: Oops: 0000000096000004 [#1] SMP
Modules linked in:
CPU: 56 UID: 2953037534 PID: 1253231 Comm: php-cgi8.4 Not tainted 6.18.45-i2-ampere #1146 NONE
[..]
pc : ceph_mds_check_access+0xd4/0x550
lr : ceph_mds_check_access+0xc8/0x550
[...]
Call trace:
ceph_mds_check_access+0xd4/0x550 (P)
ceph_atomic_open+0x138/0xbe8
path_openat+0xa24/0xfa8
do_filp_open+0x94/0x158
do_sys_openat2+0x88/0xf8
Published: 2026-09-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free leading to kernel crash or privilege escalation
Action: Apply patch
AI Analysis

Impact

In the Linux kernel’s Ceph integration, a race condition in ceph_mds_check_access() can trigger a use‑after‑free when an MDS session is reopened. The code walks a pointer to the session’s capability list without holding its protecting mutex, allowing a concurrent reopen to deallocate the memory while it is still being read. This flaw can cause a kernel fault, triggering an Oops and potentially letting a local attacker gain privileged code execution or crash the system.

Affected Systems

The flaw resides in the Linux kernel. No vendor or product version is explicitly listed in the advisory, but the relevant code paths appear to target recent Ceph‑enabled kernels (kernel version 6.18.45 in the reproduced crash). An attacker would need access to a node running the affected kernel with Ceph MD‑S support. The vulnerability is not tied to a particular vendor in the data, so all affected Linux distributions that ship a vulnerable kernel should be considered at risk.

Risk and Exploitability

The CVSS score is 9.8, indicating a severe risk. Exploitability is low according to the EPSS (<1%), and the vulnerability is not yet listed in CISA’s KEV catalog. The flaw is local; it requires the ability to open files through the Ceph filesystem from an unprivileged or compromised process. If an attacker can trigger a session reopen while another process is accessing the capability list, a kernel crash or privilege escalation may ensue.

Generated by OpenCVE AI on September 18, 2026 at 03:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Identify the kernel version in use and verify whether it contains the fix; update to a patched release from a trusted vendor
  • Apply the vendor’s official patch or upgrade the Linux distribution to a kernel that incorporates the concurrency guard around ceph_mds_check_access()
  • If a patch is not yet available, restrict Ceph client access on the node or disable Ceph mounting until the kernel is updated
  • Monitor system logs for kernel oops messages and verify that the issue is resolved after applying the fix

Generated by OpenCVE AI on September 18, 2026 at 03:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ceph: lock mutex in ceph_mds_check_access() MDS session OPEN handling replaces mdsc->s_cap_auths under mdsc->mutex, freeing the previous array and its strings. ceph_mds_check_access() traverses this array without holding the mutex. A concurrent session reopen can therefore free the array while it is being inspected, resulting in a use-after-free like this: Unable to handle kernel paging request at virtual address 003aaad64b2c8bb9 [...] Internal error: Oops: 0000000096000004 [#1] SMP Modules linked in: CPU: 56 UID: 2953037534 PID: 1253231 Comm: php-cgi8.4 Not tainted 6.18.45-i2-ampere #1146 NONE [..] pc : ceph_mds_check_access+0xd4/0x550 lr : ceph_mds_check_access+0xc8/0x550 [...] Call trace: ceph_mds_check_access+0xd4/0x550 (P) ceph_atomic_open+0x138/0xbe8 path_openat+0xa24/0xfa8 do_filp_open+0x94/0x158 do_sys_openat2+0x88/0xf8
Title ceph: lock mutex in ceph_mds_check_access()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:41:05.472Z

Reserved: 2026-09-11T19:38:34.780Z

Link: CVE-2026-89990

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:10.133

Modified: 2026-09-16T15:18:22.800

Link: CVE-2026-89990

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:00:03Z

Weaknesses