CVE-2026-68153
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
libceph: remove debugfs files before client teardown
ceph_destroy_client() tears down the monitor client before removing the per-client debugfs files. A concurrent read of the monmap debugfs file can enter monmap_show() after ceph_monc_stop() has freed monc->monmap, triggering a use-after-free.
Remove the debugfs files before stopping the OSD and monitor clients. debugfs_remove() drains active handlers and prevents new accesses, so the debugfs callbacks can no longer race the rest of client teardown.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 76aa844d5b2fb8c839180d3f5874e333b297e5fd < fc1010e7e0204ece6cc0f9af4f473e9553535eab | affected |
| Linux | Linux | 76aa844d5b2fb8c839180d3f5874e333b297e5fd < d3dc8889d39a676bf840132bd5c5c48cb0daba23 | affected |
| Linux | Linux | 76aa844d5b2fb8c839180d3f5874e333b297e5fd < 8f5a3abc54ba24dbceb14cc3a719908c4f688091 | affected |
| Linux | Linux | 76aa844d5b2fb8c839180d3f5874e333b297e5fd < b9fedda2f628e030384228de0dafc574b7fb0c2f | affected |
| Linux | Linux | 76aa844d5b2fb8c839180d3f5874e333b297e5fd < e4c804726c4afce3ba648b982d564f6af2cfa328 | affected |
| Linux | Linux | 2.6.34 | affected |
| Linux | Linux | 0 < 2.6.34 | unaffected |
| Linux | Linux | 6.6.148 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.101 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.42 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.6 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc5 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/fc1010e7e0204ece6cc0f9af4f473e9553535eab
- https://git.kernel.org/stable/c/d3dc8889d39a676bf840132bd5c5c48cb0daba23
- https://git.kernel.org/stable/c/8f5a3abc54ba24dbceb14cc3a719908c4f688091
- https://git.kernel.org/stable/c/b9fedda2f628e030384228de0dafc574b7fb0c2f
- https://git.kernel.org/stable/c/e4c804726c4afce3ba648b982d564f6af2cfa328
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.