๐Ÿ” CVE Alert

CVE-2026-89656

CRITICAL 9.8

libceph: reject buckets with mismatched CRUSH ids

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: libceph: reject buckets with mismatched CRUSH ids crush_decode() stores bucket data by array slot, and the mapper later derives the per-bucket workspace index from the decoded bucket id. A malformed map can therefore make one bucket reuse another bucket's workspace by encoding an id different from -1 - slot. For uniform buckets, the second replica selection expands the source bucket's permutation into that aliased workspace buffer. If the source bucket is larger than the aliased bucket, the write runs past the smaller permutation array and can escape the kvmalloc'd CRUSH workspace. KASAN reports a slab OOB write of 4 bytes in bucket_perm_choose(). Reject buckets whose encoded id does not match their array slot. Valid CRUSH maps already use the canonical negative id corresponding to the bucket slot, so this restores the invariant expected by work->work[-1 - in->id] without changing valid map behavior.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
66a0e2d579dbec5c676cfe446234ffebb267c564 < ee59040d6ed1a5f8d10d27174b8f32c90ca8e89a 66a0e2d579dbec5c676cfe446234ffebb267c564 < baad5875fdd2f5e248250fc3519bb045d64f1716 66a0e2d579dbec5c676cfe446234ffebb267c564 < 4aeb93daadf388e72073abc204312dd364eeb30a 66a0e2d579dbec5c676cfe446234ffebb267c564 < 6e5c6ce252b1eccfd41670a5cf95ab44f7ba7022 66a0e2d579dbec5c676cfe446234ffebb267c564 < 3516a4131c4e45d62ee4e42e82c36930e8c1fbbd 66a0e2d579dbec5c676cfe446234ffebb267c564 < 00562ccd4e88d092b9b851df50fad20442bfeb24 66a0e2d579dbec5c676cfe446234ffebb267c564 < 79900d978158b2d80eef952fc41b9e4dc58d7b83 66a0e2d579dbec5c676cfe446234ffebb267c564 < 3cde4a8302301679937474a5f7a851394cc1bd11
Linux / Linux
4.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/ee59040d6ed1a5f8d10d27174b8f32c90ca8e89a git.kernel.org: https://git.kernel.org/stable/c/baad5875fdd2f5e248250fc3519bb045d64f1716 git.kernel.org: https://git.kernel.org/stable/c/4aeb93daadf388e72073abc204312dd364eeb30a git.kernel.org: https://git.kernel.org/stable/c/6e5c6ce252b1eccfd41670a5cf95ab44f7ba7022 git.kernel.org: https://git.kernel.org/stable/c/3516a4131c4e45d62ee4e42e82c36930e8c1fbbd git.kernel.org: https://git.kernel.org/stable/c/00562ccd4e88d092b9b851df50fad20442bfeb24 git.kernel.org: https://git.kernel.org/stable/c/79900d978158b2d80eef952fc41b9e4dc58d7b83 git.kernel.org: https://git.kernel.org/stable/c/3cde4a8302301679937474a5f7a851394cc1bd11