CVE-2026-89648: ceph: cap delegated inode count in ceph_parse_deleg_inos()

Published Sep 11, 2026
·
Updated

ceph: cap delegated inode count in cephparsedeleginos()

Affected Software

1 affected component
ceph Linux kernel (Ceph client)

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ceph (Linux kernel) to a version that resolves this vulnerability.

    Fixed in resolved

Event History

Sep 11, 2026
CVE Published
via MITRE·07:45 PM
Data Sourced
via MITRE·07:45 PM
DescriptionSeverity
Data Sourced
via NVD·08:19 PM
DescriptionSeverity
Sep 13, 2026
Data Sourced
via Microsoft·08:09 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Linux kernel Ceph clients that process MDS create-with-delegation replies are exposed when the replying MDS is malicious or compromised. The affected parsing occurs on delegated inode intervals supplied by that MDS.

2

What can a malicious MDS do to trigger resource exhaustion?

It can provide a very large interval length, many intervals in one reply, duplicate intervals, or repeated replies. These inputs could make the client spend excessive time inserting inode entries or grow its delegated-inode xarray without limit.

3

How does the resolved code limit the impact?

The fix tracks delegated inode entries per MDS session and prevents the count from exceeding CEPH_MAX_DELEG_INOS. The counter is increased only during insertion, so repeated or oversized delegation data cannot grow the per-session population beyond that cap.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203