CVE-2026-80528: ceph: avoid fs reclaim while using current->journal_info

Published Aug 26, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

ceph: avoid fs reclaim while using current->journalinfo

handlereply() stores a cephmdsrequest pointer in current->journalinfo while filling the inode and dentry cache from an MDS reply.

An allocation in this section can enter direct reclaim and prune dentries from another filesystem. If this dirties an ext4 inode, ext4 starts a JBD2 transaction. JBD2 interprets the Ceph request in current->journalinfo as a journal handle and dereferences the request's rtid as htransaction, causing a kernel crash, e.g.:

Unable to handle kernel paging request at virtual address 00000000077b4818 [...] Internal error: Oops: 0000000096000004 [#1] SMP Modules linked in: CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G W 6.18.38-i3 #1113 NONE [...] Workqueue: ceph-msgr cephconworkfn pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : jbd2journalstart+0x2c/0x208 lr : ext4journalstartsb+0x100/0x178 [...] Call trace: jbd2journalstart+0x2c/0x208 (P) ext4journalstartsb+0x100/0x178 ext4dirtyinode+0x3c/0x90 markinodedirty+0x58/0x400 iput.part.0+0x2b0/0x370 iput+0x18/0x30 dentryunlinkinode+0xc0/0x158 dentrykill+0x80/0x250 shrinkdentrylist+0x90/0x130 prunedcachesb+0x60/0x98 supercachescan+0xe8/0x190 doshrinkslab+0x174/0x388 shrinkslab+0xd8/0x4c0 shrinknode+0x31c/0x908 dotrytofreepages+0xd0/0x508 trytofreepages+0x11c/0x238 allocfrozenpagesnoprof+0x4d0/0xdd0 folioallocnoprof+0x18/0x70 filemapgetfolio+0x248/0x440 cephreaddirprepopulate+0x570/0x9e8 mdsdispatch+0x1424/0x1ba0 cephconprocessmessage+0x74/0xa0 cephconv1tryread+0x3a0/0x1510 cephconworkfn+0x260/0x460

Enter a scoped NOFS allocation context and leave it after clearing journalinfo. This prevents filesystem reclaim from recursing into another filesystem while the field contains Ceph-private data.

Affected Software

2 affected components
Linux Kernel
Ceph MDS

Event History

Aug 26, 2026
CVE Published
via MITRE·02:37 PM
Data Sourced
via MITRE·02:37 PM
Description
Data Sourced
via NVD·03:17 PM
Description

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203