Junglewise Threat Intelligence

CVE-2026-89657: Linux kernel libceph OSD extent map validation denial of service

CVE-2026-89657 · Severity: high · CVSS 7.5 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Ceph client library processes sparse-read replies from Ceph Object Storage Daemons (OSDs). A malicious or compromised OSD can send a crafted reply with invalid extent maps that causes the kernel to advance its message buffer cursor beyond its bounds, triggering a crash. This affects any system using Ceph storage and accepting data from an authenticated OSD peer.

Technical details

The vulnerability exists in net/ceph/osd_client.c:osd_sparse_read(), which validates that sparse-read data lengths match summed extent lengths but fails to validate that OSD-supplied extents are monotonic, non-overlapping, and lie within the original request range. A malformed authenticated OSD reply can advertise a far-forward extent offset with matching data length, causing the client to advance the message-data cursor beyond the request buffer and hit a BUG_ON assertion in ceph_msg_data_next(). The fix adds a sparse_extent_map_valid() function to reject extent maps that overflow, move backwards, overlap, or extend outside the original sparse-read request before cursor advancement. The validation is performed in the CEPH_SPARSE_READ_DATA_LEN state.

Affected products

  • Linux Linux kernel 5.14 and later (sparse read support introduced in v5.14)

Timeline

  • 2026-09-11: disclosed: Published as CVE-2026-89657
  • 2026-09-07: patched: Patch commit 058ffa81f9440c5b4714685611cf697fd3739ec9 and 201db408872ca12cf09e36bf0f560138c3dcfa1c merged to stable trees

References

Related threats