Database/Kernel, userspace & hypervisor
CephFS kernel client (ceph.ko, ceph_handle_caps): The kernel trusts snap_trace_len straight off the wire, so a
Impact
The kernel trusts snap_trace_len straight off the wire, so a malicious or compromised MDS returns 0xFFFFFFFF and the client reads far past the message buffer before any authentication state is checked. Result is a kernel out-of-bounds read on every compute node mounting CephFS - crash at minimum, memory disclosure at worst.
Who can reach it
Anything that can speak MDS protocol to a CephFS kernel client: a compromised or spoofed MDS, or an attacker with a foothold on the storage fabric who can inject cap messages toward compute nodes.
What to do
Patch the kernel on all CephFS client nodes and reboot them. In the meantime run msgr2 secure mode so cap messages cannot be injected by a non-cluster party, and keep the Ceph public network unreachable from tenant workloads.
References
Related entries
- Linux kernel (net/xfrm): When IPsec crypto offload takes a GSO segment asynchronously, the segment is unlinked from theCVE-2026-68426 · Linux kernel (net/xfrm)Critical
- Linux kernel (net/xfrm): The ESP-in-TCP send path mis-tracked scatter-gather message offsets and socket memory chargesCVE-2026-72041 · Linux kernel (net/xfrm)Critical
- Linux kernel LIO target: unbounded iSCSI TransportID parse in PR OUT reads past the parameter bufferCVE-2026-72084 · Linux kernel LIO SCSI target (PERSISTENT RESERVE OUT TransportID parsing, iSCSI FORMAT CODE 01b)Critical
- Linux kernel - NVMe-oF target DH-HMAC-CHAP authentication, drivers/nvme/target/fabrics-cmd-auth.c: The sibling of theCVE-2026-72130 · Linux kernel - NVMe-oF target DH-HMAC-CHAP authentication, drivers/nvme/target/fabrics-cmd-auth.cCritical
- Linux kernel (net/xfrm): NAT-keepalive frees the keepalive skb whenever the IPv4/IPv6 send helper returns an errorCVE-2026-72137 · Linux kernel (net/xfrm)Critical
- Linux kernel (net/xfrm): The IPsec input path validates a security association before taking the state lock, so a stateCVE-2026-72451 · Linux kernel (net/xfrm)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.