From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9DA763FA5F1 for ; Fri, 11 Sep 2026 20:01:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156870; cv=none; b=vE0bKtkkLJOsHoEVAZJemuC+U69CDp5+IR16dW7cguY9V2goV5LMHi6C0qXkzJmG2vGNtzKSRCjm3bIjiJBxCUsSHOc/fIyUsOSVFnmLdePRe/Ct1+DMdy7WKVn1RfVgEyGNUVFV1wkWwZ2EwEHa5dUHJCyBaPHJ6H8ldgQlXgo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156870; c=relaxed/simple; bh=0mqL1UAJm/aPbd/kQo8/LXWK/eXO+Z1tp9/ySMUSpdQ=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version:Content-Type; b=cv+Zapf/LUg5I3ewKaK+XfKq3Ro7GM6IZkfd1JEorM6BXwRBfExvfLDg0/xqNbgtBHDIfdmvQm/CJ2SABoJ/g9WmkXBEYjtiC41AsNgfPHnrboyP4KMYBdtzl6itxylKvUTSxf/gX5C5s57SXr/DnecR/s1aoNMwxDo1pFiXvY0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=raxG7aYM; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="raxG7aYM" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5ED011F00893; Fri, 11 Sep 2026 20:00:59 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156859; bh=uJBFaiEzlEWGbGBVZDy1eCjlw9GKelJDsi2WhRNgARw=; h=From:To:Cc:Subject:Date:Reply-To; b=raxG7aYMm+XLaysQlHLfR/je5iL3IwkAs1M+G/hiwKVKJ5hhioR00Qz15jQDjMYxU 7Hif8J8PI4MMVQgMjI+6EguK3zyXZ9Itkc5uAPNiAE2yvVMSctKeAuPeEoBIW2+lPS orgvuFAX/lUle5MPjR2bwG/2QFe1WANa+W/olArs= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89655: ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock Date: Fri, 11 Sep 2026 21:45:44 +0200 Message-ID: <2026091145-CVE-2026-89655-4433@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3636; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=/5vrmB6IEMQx8RMhDOdLXnlmsH9cOcoyzb4XYW+8WyA=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIiuf3j013T3rgXO69RuZbI3tC1ludptbfnxcdkTeq tEjsz2jI5aFQZCJQVZMkeXLNp6j+ysOKXoZ2p6GmcPKBDKEgYtTACby0JlhfuxhRcnXPZwBR+47 yE58kz15wgTFDoYFx6Y9bQhQnWTLfVziTG7eSo9PGWtbAQ== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock list_for_each_entry() iterates ci->i_cap_flush_list but drops i_ceph_lock to send cap messages. During the unlock window, handle_cap_flush_ack() can acquire i_ceph_lock, detach cf entries with tid <= flush_tid from the list, release i_ceph_lock, and free them via ceph_free_cap_flush() outside any lock. When the original thread reacquires i_ceph_lock and the for-loop macro advances via cf = list_next_entry(cf, i_list), it dereferences cf->i_list.next on freed memory. The race timeline: __kick_flushing_caps() handle_cap_flush_ack() ----------------------- ----------------------- holds i_ceph_lock <--- iterates to cf (tid=10) prepares FLUSH message drops i_ceph_lock <--- __send_cap() ── FLUSH(tid=10) MDS sends FLUSH_ACK(tid=10) ---> acquires i_ceph_lock cf->tid(10) <= flush_tid(10), detaches cf from i_cap_flush_list drops i_ceph_lock ceph_free_cap_flush(cf) <- frees it! acquires i_ceph_lock <--- for-loop advances: cf = list_next_entry(cf, i_list) -- UAF on freed cf->i_list.next The cf was just sent by __kick_flushing_caps itself via __send_cap(). The MDS may respond with FLUSH_ACK quickly enough that handle_cap_flush_ack() frees cf before __kick_flushing_caps can finish the iteration. Fix by converting to a manual while loop: save the next pointer under i_ceph_lock before dropping it, then use the saved pointer after reacquiring, so the potentially-freed cf is never accessed again. The Linux kernel CVE team has assigned CVE-2026-89655 to this issue. Affected and fixed versions =========================== Fixed in 6.12.109 with commit 2701431aa3cc8b23efe6890182e7b04f5e76fab5 Fixed in 6.18.50 with commit fe46746087b5b9c5bb2d022df6c7819218494ced Fixed in 7.2.4 with commit 2dba24dcd5050be4b7b119e6f0b01f62203b5d26 Fixed in 7.3-rc1 with commit 7af4c4f01305b0935adf6d4301b1ec407025485d Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89655 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/ceph/caps.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/2701431aa3cc8b23efe6890182e7b04f5e76fab5 https://git.kernel.org/stable/c/fe46746087b5b9c5bb2d022df6c7819218494ced https://git.kernel.org/stable/c/2dba24dcd5050be4b7b119e6f0b01f62203b5d26 https://git.kernel.org/stable/c/7af4c4f01305b0935adf6d4301b1ec407025485d