Out-of-bounds read in Linux kernel - CVE-2026-89651
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the Ceph MDS client handle_session() function when processing MDSCapAuth records in a CEPH_SESSION_OPEN message. A remote attacker can send a specially crafted session-open message to cause a denial of service.
Only CEPH_SESSION_OPEN messages with a message version of 6 or later are affected.