Executive brief
A vulnerability was identified in the Linux kernel's Ceph network storage client that could lead to a system crash or unauthorized memory access. The issue occurs when the system attempts to connect to a storage cluster and simultaneously receives updates about the cluster's layout, causing a conflict in how memory is managed. An exploit could potentially allow an attacker to disrupt storage services or gain a foothold in the system.
Technical details
A use-after-free vulnerability exists in the libceph module of the Linux kernel due to a race condition in the have_mon_and_osd_map() function. The vulnerability occurs because the wait loop in __ceph_open_session() dereferences monmap and osdmap pointers without holding the necessary mutexes (client->monc.mutex and client->osdc.lock), while concurrent threads may be freeing and replacing these maps. An attacker could potentially trigger this race condition during the mount process to cause a kernel panic or achieve arbitrary code execution. The fix involves rewriting the wait loop to ensure proper locking is maintained during map validation and improving timeout handling.
Affected products
- Linux Linux Kernel 6.14-rc2 and earlier versions
Timeline
- 2025-11-03: other: Patch authored
- 2025-12-07: patched: Patch committed to stable tree
- 2025-12-16: advisory: CVE published
References
- https://git.kernel.org/stable/c/05ec43e9a9de67132dc8cd3b22afef001574947f
- https://git.kernel.org/stable/c/076381c261374c587700b3accf410bdd2dba334e
- https://git.kernel.org/stable/c/183ad6e3b651e8fb0b66d6a2678f4b80bfbba092
- https://git.kernel.org/stable/c/3fc43120b22a3d4f1fbeff56a35ce2105b6a5683
- https://git.kernel.org/stable/c/7c8ccdc1714d9fabecd26e1be7db1771061acc6e
- https://git.kernel.org/stable/c/bb4910c5fd436701faf367e1b5476a5a6d2aff1c
- https://git.kernel.org/stable/c/e08021b3b56b2407f37b5fe47b654be80cc665fb