CVE-2026-89990

Source
https://cve.org/CVERecord?id=CVE-2026-89990
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89990.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89990
Downstream
Published
2026-09-16T10:33:04Z
Modified
2026-09-18T03:46:16Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ceph: lock mutex in ceph_mds_check_access()
Details

In the Linux kernel, the following vulnerability has been resolved:

ceph: lock mutex in ceph_mds_check_access()

MDS session OPEN handling replaces mdsc->s_cap_auths under mdsc->mutex, freeing the previous array and its strings.

ceph_mds_check_access() traverses this array without holding the mutex. A concurrent session reopen can therefore free the array while it is being inspected, resulting in a use-after-free like this:

Unable to handle kernel paging request at virtual address 003aaad64b2c8bb9 [...] Internal error: Oops: 0000000096000004 [#1] SMP Modules linked in: CPU: 56 UID: 2953037534 PID: 1253231 Comm: php-cgi8.4 Not tainted 6.18.45-i2-ampere #1146 NONE [..] pc : ceph_mds_check_access+0xd4/0x550 lr : ceph_mds_check_access+0xc8/0x550 [...] Call trace: ceph_mds_check_access+0xd4/0x550 (P) ceph_atomic_open+0x138/0xbe8 path_openat+0xa24/0xfa8 do_filp_open+0x94/0x158 do_sys_openat2+0x88/0xf8

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89990.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
596afb0b8933ba6ed7227adcc538db26feb25c74
Fixed
729c1ff670ece6f3d4b1738365a0b2f90d487523
Fixed
ca5bfea2045ef2eb3305cf2a9d8da549b76c37d3
Fixed
df1a97d5313fccadb08390306d49b194fb027392
Fixed
a61c6ae1dae2611082b831b4aaa780878099c012

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89990.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.10.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89990.json"