From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-89652: ceph: bound copied dentry name length in NFS export get_name
Date: Fri, 11 Sep 2026 21:45:41 +0200 [thread overview]
Message-ID: <2026091144-CVE-2026-89652-3efa@gregkh> (raw)
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
ceph: bound copied dentry name length in NFS export get_name
ceph_get_name() copies the MDS-supplied name into the caller's
NAME_MAX-sized buffer with memcpy(name, rinfo->dname, rinfo->dname_len)
and then writes name[rinfo->dname_len] = 0, without checking dname_len
against NAME_MAX. A malicious or buggy MDS that returns a LOOKUPNAME reply
with dname_len > NAME_MAX overflows the buffer. __get_snap_name() copies
rde->name / rde->name_len the same unchecked way.
Impact: a malicious or compromised Ceph MDS overflows the NAME_MAX name
buffer in a client's NFS-export get_name path, a slab out-of-bounds write
reported by KASAN. Reachable when a CephFS mount is re-exported over NFS.
Add ceph_export_copy_name(), which rejects lengths above NAME_MAX with
-ENAMETOOLONG before the copy, and use it in both ceph_get_name() and
__get_snap_name().
The Linux kernel CVE team has assigned CVE-2026-89652 to this issue.
Affected and fixed versions
===========================
Issue introduced in 3.15 with commit 19913b4eac4a230dccb548931358398f45dabe4c and fixed in 6.12.109 with commit 61d9f27b191b838b96b697ce0bfaee39a138243a
Issue introduced in 3.15 with commit 19913b4eac4a230dccb548931358398f45dabe4c and fixed in 6.18.50 with commit 06fb5e623cdc2402d6bb29be94d9beb9a826ffec
Issue introduced in 3.15 with commit 19913b4eac4a230dccb548931358398f45dabe4c and fixed in 7.2.4 with commit e7c2fd3893a7f7fcd7e8cf0b2c6348bb1e893df6
Issue introduced in 3.15 with commit 19913b4eac4a230dccb548931358398f45dabe4c and fixed in 7.3-rc1 with commit eff8013c5a8916613c742ae5a2cc341cb605c0ae
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-89652
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
fs/ceph/export.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/61d9f27b191b838b96b697ce0bfaee39a138243a
https://git.kernel.org/stable/c/06fb5e623cdc2402d6bb29be94d9beb9a826ffec
https://git.kernel.org/stable/c/e7c2fd3893a7f7fcd7e8cf0b2c6348bb1e893df6
https://git.kernel.org/stable/c/eff8013c5a8916613c742ae5a2cc341cb605c0ae
reply other threads:[~2026-09-11 20:00 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026091144-CVE-2026-89652-3efa@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=cve@kernel.org \
--cc=gregkh@kernel.org \
--cc=linux-cve-announce@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox