All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-89652: ceph: bound copied dentry name length in NFS export get_name
@ 2026-09-11 19:45 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:45 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

ceph: bound copied dentry name length in NFS export get_name

ceph_get_name() copies the MDS-supplied name into the caller's
NAME_MAX-sized buffer with memcpy(name, rinfo->dname, rinfo->dname_len)
and then writes name[rinfo->dname_len] = 0, without checking dname_len
against NAME_MAX. A malicious or buggy MDS that returns a LOOKUPNAME reply
with dname_len > NAME_MAX overflows the buffer. __get_snap_name() copies
rde->name / rde->name_len the same unchecked way.

Impact: a malicious or compromised Ceph MDS overflows the NAME_MAX name
buffer in a client's NFS-export get_name path, a slab out-of-bounds write
reported by KASAN. Reachable when a CephFS mount is re-exported over NFS.

Add ceph_export_copy_name(), which rejects lengths above NAME_MAX with
-ENAMETOOLONG before the copy, and use it in both ceph_get_name() and
__get_snap_name().

The Linux kernel CVE team has assigned CVE-2026-89652 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 3.15 with commit 19913b4eac4a230dccb548931358398f45dabe4c and fixed in 6.12.109 with commit 61d9f27b191b838b96b697ce0bfaee39a138243a
	Issue introduced in 3.15 with commit 19913b4eac4a230dccb548931358398f45dabe4c and fixed in 6.18.50 with commit 06fb5e623cdc2402d6bb29be94d9beb9a826ffec
	Issue introduced in 3.15 with commit 19913b4eac4a230dccb548931358398f45dabe4c and fixed in 7.2.4 with commit e7c2fd3893a7f7fcd7e8cf0b2c6348bb1e893df6
	Issue introduced in 3.15 with commit 19913b4eac4a230dccb548931358398f45dabe4c and fixed in 7.3-rc1 with commit eff8013c5a8916613c742ae5a2cc341cb605c0ae

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-89652
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	fs/ceph/export.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/61d9f27b191b838b96b697ce0bfaee39a138243a
	https://git.kernel.org/stable/c/06fb5e623cdc2402d6bb29be94d9beb9a826ffec
	https://git.kernel.org/stable/c/e7c2fd3893a7f7fcd7e8cf0b2c6348bb1e893df6
	https://git.kernel.org/stable/c/eff8013c5a8916613c742ae5a2cc341cb605c0ae

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-11 20:00 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:45 CVE-2026-89652: ceph: bound copied dentry name length in NFS export get_name Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.