๐Ÿ” CVE Alert

CVE-2026-89655

CRITICAL 9.8

ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock list_for_each_entry() iterates ci->i_cap_flush_list but drops i_ceph_lock to send cap messages. During the unlock window, handle_cap_flush_ack() can acquire i_ceph_lock, detach cf entries with tid <= flush_tid from the list, release i_ceph_lock, and free them via ceph_free_cap_flush() outside any lock. When the original thread reacquires i_ceph_lock and the for-loop macro advances via cf = list_next_entry(cf, i_list), it dereferences cf->i_list.next on freed memory. The race timeline: __kick_flushing_caps() handle_cap_flush_ack() ----------------------- ----------------------- holds i_ceph_lock <--- iterates to cf (tid=10) prepares FLUSH message drops i_ceph_lock <--- __send_cap() โ”€โ”€ FLUSH(tid=10) MDS sends FLUSH_ACK(tid=10) ---> acquires i_ceph_lock cf->tid(10) <= flush_tid(10), detaches cf from i_cap_flush_list drops i_ceph_lock ceph_free_cap_flush(cf) <- frees it! acquires i_ceph_lock <--- for-loop advances: cf = list_next_entry(cf, i_list) -- UAF on freed cf->i_list.next The cf was just sent by __kick_flushing_caps itself via __send_cap(). The MDS may respond with FLUSH_ACK quickly enough that handle_cap_flush_ack() frees cf before __kick_flushing_caps can finish the iteration. Fix by converting to a manual while loop: save the next pointer under i_ceph_lock before dropping it, then use the saved pointer after reacquiring, so the potentially-freed cf is never accessed again.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
e4500b5e35c213e0f97be7cb69328c0877203a79 < 091137821e1fc88f37e15201abf055c9494ddc61 e4500b5e35c213e0f97be7cb69328c0877203a79 < 01542430081014d80fc9e70e92d6647432ddb7fc e4500b5e35c213e0f97be7cb69328c0877203a79 < 23eb34a53a53cb1a6dab1eeee830633207ac158d e4500b5e35c213e0f97be7cb69328c0877203a79 < 19f16f04c2b014a7dd214dc1e42557d8530b16f3 e4500b5e35c213e0f97be7cb69328c0877203a79 < 2701431aa3cc8b23efe6890182e7b04f5e76fab5 e4500b5e35c213e0f97be7cb69328c0877203a79 < fe46746087b5b9c5bb2d022df6c7819218494ced e4500b5e35c213e0f97be7cb69328c0877203a79 < 2dba24dcd5050be4b7b119e6f0b01f62203b5d26 e4500b5e35c213e0f97be7cb69328c0877203a79 < 7af4c4f01305b0935adf6d4301b1ec407025485d
Linux / Linux
4.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/091137821e1fc88f37e15201abf055c9494ddc61 git.kernel.org: https://git.kernel.org/stable/c/01542430081014d80fc9e70e92d6647432ddb7fc git.kernel.org: https://git.kernel.org/stable/c/23eb34a53a53cb1a6dab1eeee830633207ac158d git.kernel.org: https://git.kernel.org/stable/c/19f16f04c2b014a7dd214dc1e42557d8530b16f3 git.kernel.org: https://git.kernel.org/stable/c/2701431aa3cc8b23efe6890182e7b04f5e76fab5 git.kernel.org: https://git.kernel.org/stable/c/fe46746087b5b9c5bb2d022df6c7819218494ced git.kernel.org: https://git.kernel.org/stable/c/2dba24dcd5050be4b7b119e6f0b01f62203b5d26 git.kernel.org: https://git.kernel.org/stable/c/7af4c4f01305b0935adf6d4301b1ec407025485d