In the Linux kernel, the following vulnerability has been resolved:
ceph: avoid fs reclaim while using current->journal_info
handle_reply() stores a ceph_mds_request pointer in
current->journal_info while filling the inode and dentry cache from
an MDS reply.
An allocation in this section can enter direct reclaim and prune
dentries from another filesystem. If this dirties an ext4 inode, ext4
starts a JBD2 transaction. JBD2 interprets the Ceph request in
current->journal_info as a journal handle and dereferences the
request's r_tid as h_transaction, causing a kernel crash, e.g.:
Unable to handle kernel paging request at virtual address 00000000077b4818 [...] Internal error: Oops: 0000000096000004 [#1] SMP Modules linked in: CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G W 6.18.38-i3 #1113 NONE [...] Workqueue: ceph-msgr cephconworkfn pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : jbd2__journal_start+0x2c/0x208 lr : ext4journalstart_sb+0x100/0x178 [...] Call trace: jbd2journal_start+0x2c/0x208 (P) __ext4journalstart_sb+0x100/0x178 ext4dirtyinode+0x3c/0x90 __markinodedirty+0x58/0x400 iput.part.0+0x2b0/0x370 iput+0x18/0x30 dentryunlinkinode+0xc0/0x158 __dentrykill+0x80/0x250 shrinkdentrylist+0x90/0x130 prunedcachesb+0x60/0x98 supercachescan+0xe8/0x190 doshrinkslab+0x174/0x388 shrinkslab+0xd8/0x4c0 shrinknode+0x31c/0x908 dotrytofreepages+0xd0/0x508 trytofreepages+0x11c/0x238 __allocfrozenpages_noprof+0x4d0/0xdd0 __folioallocnoprof+0x18/0x70 __filemapgetfolio+0x248/0x440 cephreaddirprepopulate+0x570/0x9e8 mdsdispatch+0x1424/0x1ba0 cephconprocessmessage+0x74/0xa0 cephconv1tryread+0x3a0/0x1510 cephconworkfn+0x260/0x460
Enter a scoped NOFS allocation context and leave it after clearing
journal_info. This prevents filesystem reclaim from recursing into
another filesystem while the field contains Ceph-private data.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80528.json",
"cna_assigner": "Linux"
}