From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8775044BCB4 for ; Fri, 11 Sep 2026 20:01:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156877; cv=none; b=HEHr+zx1btXImAuOcKukOQe7VDkVaIMGcH1hJsFeFOEHSUWAm+79z2ZRNlRZY78MjM37QHnmLeADwSeF4k+4VTgvfvJ3OfSH2GGRNmKwEMK9LdsTp+jje9JouIpS62X/hVnkktyTSIpIUqojaVlIKepwpvjm9VAowDoAW+hu2jU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156877; c=relaxed/simple; bh=c+DYJWKFR3OEFL9EtxJ8DcZoPZoOLi0/gu3hvbjWnPY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=ZpanncLak/VrkZk1WdBgcxjSD5sc8OM6GCmdR6eM1TkkrIspHfz+ZFaPCTxqXBjJuFGs/N2VMAb63FzhivfyhLEhjzUvuC82ahlyzg9DEa5jclUGvsYRhOhwL53O8v1T8JOK2mxIgKbf25FmAjSDqI/iFdgOYfdcGKq3UNAOW84= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=ns5uGZav; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="ns5uGZav" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 3E6201F00899; Fri, 11 Sep 2026 20:01:04 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156865; bh=5/So+G6Z8EMTKLmj/QwrXWQZpF+5G//LnQPw1L6r49c=; h=From:To:Cc:Subject:Date:Reply-To; b=ns5uGZavvc3AqDTh3tvoIqExbk16oBsobK8Ml1xe0HDciLe7m+0JQaOmBpRzHkIBH YRkSZBP7gVX7VWgIvrAWVRCmEPIbemrVEpod6+a/ua7Gy8aQm/msc8tK6ugMgzIK2b ix8/3BPweT2uQcqaDfzZq7sX60umwsdLM4tiRPFM= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89657: libceph: validate OSD extent maps before cursor advance Date: Fri, 11 Sep 2026 21:45:46 +0200 Message-ID: <2026091145-CVE-2026-89657-e173@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3178; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=jZqPvCUe6EnLj4o9BPHaZeIIdFUqKmVD/ymaONK8Szg=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIisP8JmuXiS41y9n1cdfUzi3fNvtPX2NSGSQpxFv3 cI1F+5UdMSyMAgyMciKKbJ82cZzdH/FIUUvQ9vTMHNYmUCGMHBxCsBEtEoYFkxeeOTdJRfJJSpn 8nVa+jwXG/adPs6wYFqySFL4Jb41TTekq7ernutd66jzHAA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: libceph: validate OSD extent maps before cursor advance net/ceph/osd_client.c:osd_sparse_read() validates that the sparse-read data length matches the summed extent lengths, but it does not validate that each OSD-supplied extent is monotonic and lies inside the original request range. A malformed authenticated OSD reply can advertise a far-forward nonzero extent offset with a matching data length and make the client advance the message-data cursor beyond the request buffer. This reaches the BUG_ON(!*length) assertion in ceph_msg_data_next() from the client receive path. Impact: A malicious or compromised authenticated Ceph OSD peer can crash a kernel Ceph client via a malformed sparse-read reply. Reject sparse extent maps that overflow, move backwards, overlap, or extend outside the original sparse-read request before advancing the cursor. [ idryomov: perform sparse_extent_map_valid() check a bit earlier, in CEPH_SPARSE_READ_DATA_LEN instead of CEPH_SPARSE_READ_DATA_PRE state ] The Linux kernel CVE team has assigned CVE-2026-89657 to this issue. Affected and fixed versions =========================== Issue introduced in 6.6 with commit f628d799972799023d32c2542bb2639eb8c4f84e and fixed in 6.12.109 with commit 058ffa81f9440c5b4714685611cf697fd3739ec9 Issue introduced in 6.6 with commit f628d799972799023d32c2542bb2639eb8c4f84e and fixed in 6.18.50 with commit 2571b35883268a266554e80d368e67fdfea7fb9d Issue introduced in 6.6 with commit f628d799972799023d32c2542bb2639eb8c4f84e and fixed in 7.2.4 with commit 201db408872ca12cf09e36bf0f560138c3dcfa1c Issue introduced in 6.6 with commit f628d799972799023d32c2542bb2639eb8c4f84e and fixed in 7.3-rc1 with commit 9ec08b7499a62c6d4afa93d36ab47a43fcad57d1 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89657 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/ceph/osd_client.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/058ffa81f9440c5b4714685611cf697fd3739ec9 https://git.kernel.org/stable/c/2571b35883268a266554e80d368e67fdfea7fb9d https://git.kernel.org/stable/c/201db408872ca12cf09e36bf0f560138c3dcfa1c https://git.kernel.org/stable/c/9ec08b7499a62c6d4afa93d36ab47a43fcad57d1