Junglewise Threat Intelligence

CVE-2026-89647: Linux kernel Ceph cap reclaim busy loop denial of service

CVE-2026-89647 · Severity: high · CVSS 7.5 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Ceph distributed filesystem client has a flaw in its cap reclaim mechanism that causes excessive CPU consumption under certain conditions. When the system is not under memory pressure but has valid directory leases, the reclaim process enters a busy loop that performs 500+ pointless operations per second, consuming significant CPU resources and degrading server performance.

Technical details

The vulnerability exists in ceph_cap_reclaim_work() and the directory lease walk logic. The ceph_trim_dentries() function returns -EAGAIN whenever it exhausts its scan budget, causing the reclaim work to re-queue itself indefinitely. The issue is exacerbated when expire_dir_lease is false: __dir_lease_check() returns TOUCH for every valid lease, causing the function to rewrite the dentry list, reset timestamps, and always drain the scan budget, guaranteeing the -EAGAIN return. An attacker can trigger this condition by maintaining valid directory leases without applying actual cap pressure, causing the kernel to spin in a busy loop consuming CPU without freeing any resources. The fix involves returning KEEP instead of TOUCH when expire_dir_lease is false, only returning -EAGAIN when something was actually freed, and bailing out when no progress is made and there is no cap pressure.

Affected products

  • Linux Linux kernel <UNKNOWN>

Timeline

  • 2026-09-11: disclosed
  • 2026-09-11: patched: Fix applied in same patch

Related threats