Description
In the Linux kernel, the following vulnerability has been resolved:

ceph: properly decrypt filenames in vmalloc() buffers

The fscrypt subsystem uses the scatterlist crypto API, inheriting its
requirement that any buffers are in the linear mapping region. However,
the messenger client uses kvmalloc() to create buffers for messages,
which will occasionally place those buffers in the vmalloc() region when
physical memory fragmentation doesn't permit a large enough kmalloc().
The various callers of ceph_fname_to_usr() directly pass (slices of) raw
messages from the MDS without considering that the messages may be in
vmalloc() buffers, resulting in oopses especially on non-x86 platforms
(see 'Closes:' for more details and a reproducer).

Make ceph_fname_to_usr() explicitly tolerant of vmalloc()-allocated
fname->ctext, fname->name, and/or oname->name buffers, using `tname`
(which, when non-null, must be a linear address; when null, is briefly
allocated as necessary) as a bounce buffer to avoid passing any
inappropriate addresses to fscrypt_fname_disk_to_usr().

Additionally change parse_reply_info_readdir() -- the only function to
supply its own `tname` -- to follow the new "tname must never come from
vmalloc()" rule by passing NULL when the message is not in the linear
region. Though this causes a per-dentry kmalloc()+kfree(), this overhead
exists only when processing the minority of messages that spill into
vmalloc(). My (crude) testing puts this at only about 1 in 8,000 readdir
messages. Still, if the overhead proves unreasonable in the future, it
is easy enough to mitigate: a future change could allocate a bounce
buffer in parse_reply_info_readdir() and use that as `tname` instead.
Published: 2026-09-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash causing denial of service
Action: Patch Now
AI Analysis

Impact

A flaw in the Linux kernel’s fscrypt integration allows ceph messenger to pass buffers allocated from the vmalloc region to a decryption routine that expects linear memory. This mismatch causes an oops, leading to a kernel crash with no elevated privileges. The effect is that any system running a vulnerable kernel can be forced into a denial‑of‑service condition, potentially disrupting all user processes.

Affected Systems

All Linux kernel installations are susceptible because the issue is tied to the core fscrypt subsystem. No specific version range is listed in the available data, so a check against local kernel sources and the patch logs is required.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical impact and wide exploitation potential. The EPSS score is listed as < 1%, meaning the probability of exploitation is low at present, and the vulnerability is not in the CISA KEV catalog. The likely attack vector is a local kernel exploit through ceph communication, as the problem occurs when the messenger client creates messages that land in the vmalloc region. A local attacker could trigger the oops by interacting with ceph or by controlling memory layout to force allocation into the problematic region.

Generated by OpenCVE AI on September 18, 2026 at 06:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to the latest stable release that includes the fix committed in the ceph subsystem.
  • If updating immediately is not possible, limit Ceph client traffic to trusted hosts or reject untrusted connections to reduce exposure.
  • Consider disabling fscrypt on affected systems until the patch is applied if the functionality is optional.

Generated by OpenCVE AI on September 18, 2026 at 06:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Fri, 18 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-680

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ceph: properly decrypt filenames in vmalloc() buffers The fscrypt subsystem uses the scatterlist crypto API, inheriting its requirement that any buffers are in the linear mapping region. However, the messenger client uses kvmalloc() to create buffers for messages, which will occasionally place those buffers in the vmalloc() region when physical memory fragmentation doesn't permit a large enough kmalloc(). The various callers of ceph_fname_to_usr() directly pass (slices of) raw messages from the MDS without considering that the messages may be in vmalloc() buffers, resulting in oopses especially on non-x86 platforms (see 'Closes:' for more details and a reproducer). Make ceph_fname_to_usr() explicitly tolerant of vmalloc()-allocated fname->ctext, fname->name, and/or oname->name buffers, using `tname` (which, when non-null, must be a linear address; when null, is briefly allocated as necessary) as a bounce buffer to avoid passing any inappropriate addresses to fscrypt_fname_disk_to_usr(). Additionally change parse_reply_info_readdir() -- the only function to supply its own `tname` -- to follow the new "tname must never come from vmalloc()" rule by passing NULL when the message is not in the linear region. Though this causes a per-dentry kmalloc()+kfree(), this overhead exists only when processing the minority of messages that spill into vmalloc(). My (crude) testing puts this at only about 1 in 8,000 readdir messages. Still, if the overhead proves unreasonable in the future, it is easy enough to mitigate: a future change could allocate a bounce buffer in parse_reply_info_readdir() and use that as `tname` instead.
Title ceph: properly decrypt filenames in vmalloc() buffers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:15:17.217Z

Reserved: 2026-09-11T19:38:34.783Z

Link: CVE-2026-90042

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:17.450

Modified: 2026-09-21T14:17:28.387

Link: CVE-2026-90042

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:00:06Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-680

    Integer Overflow to Buffer Overflow