SB20260827109 - Improper resource shutdown or release in Linux kernel ceph
Published: August 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-80528)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a kernel crash.
The vulnerability exists due to improper resource shutdown or release in handle_reply() in fs/ceph/mds_client.c when processing Ceph MDS replies and filling inode and dentry cache data. A remote attacker can send a specially crafted Ceph MDS reply to cause a kernel crash.
The issue occurs because Ceph-private data stored in current->journal_info may be dereferenced by another filesystem during reclaim.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/00c12f57a87f537fa8779258fb3a03003a99963e
- https://git.kernel.org/stable/c/47b745747b3aa39064724a642884f9df924ddf20
- https://git.kernel.org/stable/c/4dbb2c02558e71f93510a6461d7e798b67426b49
- https://git.kernel.org/stable/c/5b602344a49e039e792ce5a8923bcc61412ee134
- https://git.kernel.org/stable/c/79d95b43ca090426399651ed580dd9bf2db36ab8
- https://git.kernel.org/stable/c/b6a0989613072499633e761a1536428a466de7d3
- https://git.kernel.org/stable/c/c8a21660c3b90864c391164eea5622e7b5b2897c
- https://git.kernel.org/stable/c/ca5fa2380dd90a0adb01580fa6225025351a90f6