CVE-2026-89648: ceph: cap delegated inode count in ceph_parse_deleg_inos()
ceph: cap delegated inode count in cephparsedeleginos()
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ceph (Linux kernel)to a version that resolves this vulnerability.Fixed in resolved
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Linux kernel Ceph clients that process MDS create-with-delegation replies are exposed when the replying MDS is malicious or compromised. The affected parsing occurs on delegated inode intervals supplied by that MDS.
What can a malicious MDS do to trigger resource exhaustion?
It can provide a very large interval length, many intervals in one reply, duplicate intervals, or repeated replies. These inputs could make the client spend excessive time inserting inode entries or grow its delegated-inode xarray without limit.
How does the resolved code limit the impact?
The fix tracks delegated inode entries per MDS session and prevents the count from exceeding CEPH_MAX_DELEG_INOS. The counter is increased only during insertion, so repeated or oversized delegation data cannot grow the per-session population beyond that cap.