CVE-2026-89655
CVE CVE-2026-89655EUVD EUVD-2026-76567Published 2026-09-11T19:45:44.000ZLast changed 2026-09-14T12:01:49.000ZCVSS 9.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock list_for_each_entry() iterates ci->i_cap_flush_list but drops i_ceph_lock to send cap messages. During the unlock window, handle_cap_flush_ack() can acquire i_ceph_lock, detach cf entries with tid <= flush_tid from the list, release i_ceph_lock, and free them via ceph_free_cap_flush() outside any lock. When the original thread reacquires i_ceph_lock and the for-loop macro advances via cf = list_next_entry(cf, i_list), it dereferences cf->i_list.next on freed memory. The race timeline: __kick_flushing_caps() handle_cap_flush_ack() ----------------------- ----------------------- holds i_ceph_lock <--- iterates to cf (tid=10) prepares FLUSH message drops i_ceph_lock <--- __send_cap() ── FLUSH(tid=10) MDS sends FLUSH_ACK(tid=10) ---> acquires i_ceph_lock cf->tid(10) <= flush_tid(10), detaches cf from i_cap_flush_list drops i_ceph_lock ceph_free_cap_flush(cf) <- frees it! acquires i_ceph_lock <--- for-loop advances: cf = list_next_entry(cf, i_list) -- UAF on freed cf->i_list.next The cf was just sent by __kick_flushing_caps itself via __send_cap(). The MDS may respond with FLUSH_ACK quickly enough that handle_cap_flush_ack() frees cf before __kick_flushing_caps can finish the iteration. Fix by converting to a manual while loop: save the next pointer under i_ceph_lock before dropping it, then use the saved pointer after reacquiring, so the potentially-freed cf is never accessed again.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux e4500b5e35c213e0f97be7cb69328c0877203a79 <23eb34a53a53cb1a6dab1eeee830633207ac158d; patch: 6.1.188; patch: 7.3-rc1; e4500b5e35c213e0f97be7cb69328c0877203a79 <2701431aa3cc8b23efe6890182e7b04f5e76fab5; patch: 6.6.157; 4.8; patch: 0; e4500b5e35c213e0f97be7cb69328c0877203a79 <fe46746087b5b9c5bb2d022df6c7819218494ced; patch: 5.10.270; e4500b5e35c213e0f97be7cb69328c0877203a79 <091137821e1fc88f37e15201abf055c9494ddc61; e4500b5e35c213e0f97be7cb69328c0877203a79 <19f16f04c2b014a7dd214dc1e42557d8530b16f3; e4500b5e35c213e0f97be7cb69328c0877203a79 <01542430081014d80fc9e70e92d6647432ddb7fc; e4500b5e35c213e0f97be7cb69328c0877203a79 <7af4c4f01305b0935adf6d4301b1ec407025485d; e4500b5e35c213e0f97be7cb69328c0877203a79 <2dba24dcd5050be4b7b119e6f0b01f62203b5d26; patch: 6.12.109; patch: 5.15.221; patch: 6.18.50; patch: 7.2.4
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.