Answer in brief
CVE-2024-26689 records a Unknown severity vulnerability in ceph: prevent use-after-free in encode_cap_msg(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2024-26689 records a Unknown severity vulnerability in ceph: prevent use-after-free in encode_cap_msg(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=9030aaf9bf0a1eee47a154c316c789e959638b0f <8180d0c27b93a6eb60da1b08ea079e3926328214 || >=9030aaf9bf0a1eee47a154c316c789e959638b0f <70e329b440762390258a6fe8c0de93c9fdd56c77 || >=9030aaf9bf0a1eee47a154c316c789e959638b0f <f3f98d7d84b31828004545e29fd7262b9f444139 || >=9030aaf9bf0a1eee47a154c316c789e959638b0f <ae20db45e482303a20e56f2db667a9d9c54ac7e7 || >=9030aaf9bf0a1eee47a154c316c789e959638b0f <7958c1bf5b03c6f1f58e724dbdec93f8f60b96fc || >=9030aaf9bf0a1eee47a154c316c789e959638b0f <cda4672da1c26835dcbd7aec2bfed954eda9b5ef | 8180d0c27b93a6eb60da1b08ea079e3926328214, 70e329b440762390258a6fe8c0de93c9fdd56c77, f3f98d7d84b31828004545e29fd7262b9f444139, ae20db45e482303a20e56f2db667a9d9c54ac7e7, 7958c1bf5b03c6f1f58e724dbdec93f8f60b96fc, cda4672da1c26835dcbd7aec2bfed954eda9b5ef |
| Linux/Linuxgeneric | 2.6.34 | Not reported |
Published upstream
Apr 3, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ceph: prevent use-after-free in encode_cap_msg() In fs/ceph/caps.c, in encode_cap_msg(), "use after free" error was caught by KASAN at this line - 'ceph_buffer_get(arg->xattr_buf);'. This implies before the refcount could be increment here, it was freed. In same file, in "handle_cap_grant()" refcount is decremented by this line - 'ceph_buffer_put(ci->i_xattrs.blob);'. It appears that a race occurred and resource was freed by the latter line before the former line could increment it. encode_cap_msg() is called by __send_cap() and __send_cap() is called by ceph_check_caps() after calling __prep_cap(). __prep_cap() is where arg->xattr_buf is assigned to ci->i_xattrs.blob. This is the spot where the refcount must be increased to prevent "use after free" error.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=9030aaf9bf0a1eee47a154c316c789e959638b0f <8180d0c27b93a6eb60da1b08ea079e3926328214 || >=9030aaf9bf0a1eee47a154c316c789e959638b0f <70e329b440762390258a6fe8c0de93c9fdd56c77 || >=9030aaf9bf0a1eee47a154c316c789e959638b0f <f3f98d7d84b31828004545e29fd7262b9f444139 || >=9030aaf9bf0a1eee47a154c316c789e959638b0f <ae20db45e482303a20e56f2db667a9d9c54ac7e7 || >=9030aaf9bf0a1eee47a154c316c789e959638b0f <7958c1bf5b03c6f1f58e724dbdec93f8f60b96fc || >=9030aaf9bf0a1eee47a154c316c789e959638b0f <cda4672da1c26835dcbd7aec2bfed954eda9b5ef | 8180d0c27b93a6eb60da1b08ea079e3926328214, 70e329b440762390258a6fe8c0de93c9fdd56c77, f3f98d7d84b31828004545e29fd7262b9f444139, ae20db45e482303a20e56f2db667a9d9c54ac7e7, 7958c1bf5b03c6f1f58e724dbdec93f8f60b96fc, cda4672da1c26835dcbd7aec2bfed954eda9b5ef |
| Linux/Linuxgeneric | 2.6.34 | Not reported |
Published upstream
Apr 3, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ceph: prevent use-after-free in encode_cap_msg() In fs/ceph/caps.c, in encode_cap_msg(), "use after free" error was caught by KASAN at this line - 'ceph_buffer_get(arg->xattr_buf);'. This implies before the refcount could be increment here, it was freed. In same file, in "handle_cap_grant()" refcount is decremented by this line - 'ceph_buffer_put(ci->i_xattrs.blob);'. It appears that a race occurred and resource was freed by the latter line before the former line could increment it. encode_cap_msg() is called by __send_cap() and __send_cap() is called by ceph_check_caps() after calling __prep_cap(). __prep_cap() is where arg->xattr_buf is assigned to ci->i_xattrs.blob. This is the spot where the refcount must be increased to prevent "use after free" error.
Quoted source text, attributed separately from HOL analysis.