Answer in brief
CVE-2026-23201 records a Unknown severity vulnerability in ceph: fix oops due to invalid pointer for kfree() in parse_longname(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4b9aee707c4580511983a0998547f3b28514e6a6 <c9a129c82ddf82a50b4f8960d2609714ca2dbd26 || >=bb80f7618832d26f7e395f52f82b1dac76223e5f <8c9af7339de419819cfc641d551675d38ff99abf || >=101841c38346f4ca41dc1802c867da990ffb32eb <e258ed369c9e04caa7d2fd49785d753ae4034cb6 || >=101841c38346f4ca41dc1802c867da990ffb32eb <bc8dedae022ce3058659c3addef3ec4b41d15e00 || 3145b2b11492d61c512bbc59660bb823bc757f48 || 493479af8af3ab907f49e99323777d498a4fbd2b || >=6.12.42 <6.12.70 || >=6.15.10 <6.16 || >=6.16.1 <6.17 | c9a129c82ddf82a50b4f8960d2609714ca2dbd26, 8c9af7339de419819cfc641d551675d38ff99abf, e258ed369c9e04caa7d2fd49785d753ae4034cb6, bc8dedae022ce3058659c3addef3ec4b41d15e00, 6.12.70, 6.16, 6.17 |
| Linux/Linuxgeneric | 6.17 | Not reported |
Published upstream
Feb 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 14, 2026
In the Linux kernel, the following vulnerability has been resolved: ceph: fix oops due to invalid pointer for kfree() in parse_longname() This fixes a kernel oops when reading ceph snapshot directories (.snap), for example by simply running `ls /mnt/my_ceph/.snap`. The variable str is guarded by __free(kfree), but advanced by one for skipping the initial '_' in snapshot names. Thus, kfree() is called with an invalid pointer. This patch removes the need for advancing the pointer so kfree() is called with correct memory pointer. Steps to reproduce: 1. Create snapshots on a cephfs volume (I've 63 snaps in my testcase) 2. Add cephfs mount to fstab $ echo "[email protected]=/volumes/datapool/stuff/3461082b-ecc9-4e82-8549-3fd2590d3fb6 /mnt/test/stuff ceph acl,noatime,_netdev 0 0" >> /etc/fstab 3. Reboot the system $ systemctl reboot 4. Check if it's really mounted $ mount | grep stuff 5. List snapshots (expected 63 snapshots on my system) $ ls /mnt/test/stuff/.snap Now ls hangs forever and the kernel log shows the oops.
Quoted source text, attributed separately from HOL analysis.