From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B900745A2A0 for ; Fri, 11 Sep 2026 20:00:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156855; cv=none; b=WJJ042rSCW9+vSKmuDY+/75yvwYaquPEVN889zJlSz3pEnycczs77VCK8qheOFI7iJKasAL0TTOUaSMh6REZuvWYfjzyqZbU7TP1Rn5Rm7nhI5RUdDttWYjoY/bBCDBImA+W6pdQSzUx9A+3if2fuuTBacHUnuvCSxhIQxhzKjI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156855; c=relaxed/simple; bh=K9p/rogueC0v2YSkFojDEm1Wlvarr8y5KfRtgi2Mcpo=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=NjTTm2v3h89naBJjimBUKiLnIsogsHfx4cFJQ2tKcz7Sf9X4lCfk+Ymhu5iZjtcdt6KkyDam7CWM2ir2cHOpnnC5iu2GyMAKaYCLM74VthiTof80cPl7DYzs2yWnU0xyiATDLJ1uFSEPPwf7RPx5zp8Ik3txWlmbl7h0Z47SmBs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=sANDwfg6; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="sANDwfg6" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 397241F00899; Fri, 11 Sep 2026 20:00:46 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156847; bh=7BkmB8RCInNlQlX9kHgY2H5lLSOPwMIu5lnfpKAUz7Q=; h=From:To:Cc:Subject:Date:Reply-To; b=sANDwfg6W0ZiCMDBB2+eq+Ij004CfhwWDTiGllzxr6GXqAEBtZ3SWDsdfAqd4HM+V 47eQwJRQHRSjbB+108K3lup2dS/E5L0J91aulpw/BGsPLPyJ7bsa8gRH2rjw67kruC dujdcotSWXDX30L5SYz1Ztg7eux7zsDaloHqk7lo= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89652: ceph: bound copied dentry name length in NFS export get_name Date: Fri, 11 Sep 2026 21:45:41 +0200 Message-ID: <2026091144-CVE-2026-89652-3efa@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3019; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=5YF5eX4Zqjh+aZbWFvFNsWON5sqZtyuwYpgnT+YEn4U=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIiv+7vm5KezDwr6+/ATmW4UbVTl/r3stIVVwpEdz+ fFvDTMXdsSyMAgyMciKKbJ82cZzdH/FIUUvQ9vTMHNYmUCGMHBxCsBEeMUY5meF6N0TsLjtU98o 7HF2Z3/Hv2N5SQwLVld8izzsYfb8dg/3rE2rZcOWlnRIAwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ceph: bound copied dentry name length in NFS export get_name ceph_get_name() copies the MDS-supplied name into the caller's NAME_MAX-sized buffer with memcpy(name, rinfo->dname, rinfo->dname_len) and then writes name[rinfo->dname_len] = 0, without checking dname_len against NAME_MAX. A malicious or buggy MDS that returns a LOOKUPNAME reply with dname_len > NAME_MAX overflows the buffer. __get_snap_name() copies rde->name / rde->name_len the same unchecked way. Impact: a malicious or compromised Ceph MDS overflows the NAME_MAX name buffer in a client's NFS-export get_name path, a slab out-of-bounds write reported by KASAN. Reachable when a CephFS mount is re-exported over NFS. Add ceph_export_copy_name(), which rejects lengths above NAME_MAX with -ENAMETOOLONG before the copy, and use it in both ceph_get_name() and __get_snap_name(). The Linux kernel CVE team has assigned CVE-2026-89652 to this issue. Affected and fixed versions =========================== Issue introduced in 3.15 with commit 19913b4eac4a230dccb548931358398f45dabe4c and fixed in 6.12.109 with commit 61d9f27b191b838b96b697ce0bfaee39a138243a Issue introduced in 3.15 with commit 19913b4eac4a230dccb548931358398f45dabe4c and fixed in 6.18.50 with commit 06fb5e623cdc2402d6bb29be94d9beb9a826ffec Issue introduced in 3.15 with commit 19913b4eac4a230dccb548931358398f45dabe4c and fixed in 7.2.4 with commit e7c2fd3893a7f7fcd7e8cf0b2c6348bb1e893df6 Issue introduced in 3.15 with commit 19913b4eac4a230dccb548931358398f45dabe4c and fixed in 7.3-rc1 with commit eff8013c5a8916613c742ae5a2cc341cb605c0ae Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89652 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/ceph/export.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/61d9f27b191b838b96b697ce0bfaee39a138243a https://git.kernel.org/stable/c/06fb5e623cdc2402d6bb29be94d9beb9a826ffec https://git.kernel.org/stable/c/e7c2fd3893a7f7fcd7e8cf0b2c6348bb1e893df6 https://git.kernel.org/stable/c/eff8013c5a8916613c742ae5a2cc341cb605c0ae