Impact
In the Linux kernel’s Ceph integration, a race condition in ceph_mds_check_access() can trigger a use‑after‑free when an MDS session is reopened. The code walks a pointer to the session’s capability list without holding its protecting mutex, allowing a concurrent reopen to deallocate the memory while it is still being read. This flaw can cause a kernel fault, triggering an Oops and potentially letting a local attacker gain privileged code execution or crash the system.
Affected Systems
The flaw resides in the Linux kernel. No vendor or product version is explicitly listed in the advisory, but the relevant code paths appear to target recent Ceph‑enabled kernels (kernel version 6.18.45 in the reproduced crash). An attacker would need access to a node running the affected kernel with Ceph MD‑S support. The vulnerability is not tied to a particular vendor in the data, so all affected Linux distributions that ship a vulnerable kernel should be considered at risk.
Risk and Exploitability
The CVSS score is 9.8, indicating a severe risk. Exploitability is low according to the EPSS (<1%), and the vulnerability is not yet listed in CISA’s KEV catalog. The flaw is local; it requires the ability to open files through the Ceph filesystem from an unprivileged or compromised process. If an attacker can trigger a session reopen while another process is accessing the capability list, a kernel crash or privilege escalation may ensue.
OpenCVE Enrichment
Debian DLA
Debian DSA