Junglewise Threat Intelligence

CVE-2026-89649: Linux kernel Ceph xattr value length out-of-bounds read

CVE-2026-89649 · Severity: critical · CVSS 9.1 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Ceph filesystem client contains a memory disclosure vulnerability in extended attribute (xattr) handling. A malicious or compromised Ceph metadata server can craft specially-crafted file metadata that causes the kernel to copy uninitialized or sensitive adjacent heap memory to user space when an application reads file attributes. This could expose sensitive data such as cryptographic keys, authentication tokens, or other kernel memory contents to a local user.

Technical details

The vulnerability exists in the __build_xattrs() function in the Ceph filesystem driver. When parsing xattr data from the metadata server, the code reads a 32-bit value length field but fails to validate that the specified number of bytes actually exist in the received buffer before advancing the parse pointer. For all attributes except the last, the implicit bounds check occurs when parsing the next attribute's length field. However, the final attribute's length is never validated against buffer bounds. A malicious MDS can set the last attribute's value length larger than the actual buffer contents, causing __set_xattr() to record the oversized length. Subsequent getxattr(2) calls then memcpy beyond the allocation boundary into user space. Fix: add explicit ceph_decode_need() bounds validation before advancing past the value bytes.

Affected products

  • Linux Linux kernel multiple versions prior to patch

Timeline

  • 2026-09-11: disclosed

Related threats