Answer in brief
CVE-2026-89657 records a Unknown severity vulnerability in libceph: validate OSD extent maps before cursor advance. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f628d799972799023d32c2542bb2639eb8c4f84e <058ffa81f9440c5b4714685611cf697fd3739ec9 || >=f628d799972799023d32c2542bb2639eb8c4f84e <2571b35883268a266554e80d368e67fdfea7fb9d || >=f628d799972799023d32c2542bb2639eb8c4f84e <201db408872ca12cf09e36bf0f560138c3dcfa1c || >=f628d799972799023d32c2542bb2639eb8c4f84e <9ec08b7499a62c6d4afa93d36ab47a43fcad57d1 | 058ffa81f9440c5b4714685611cf697fd3739ec9, 2571b35883268a266554e80d368e67fdfea7fb9d, 201db408872ca12cf09e36bf0f560138c3dcfa1c, 9ec08b7499a62c6d4afa93d36ab47a43fcad57d1 |
| Linux/Linuxgeneric | 6.6 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: libceph: validate OSD extent maps before cursor advance net/ceph/osd_client.c:osd_sparse_read() validates that the sparse-read data length matches the summed extent lengths, but it does not validate that each OSD-supplied extent is monotonic and lies inside the original request range. A malformed authenticated OSD reply can advertise a far-forward nonzero extent offset with a matching data length and make the client advance the message-data cursor beyond the request buffer. This reaches the BUG_ON(!*length) assertion in ceph_msg_data_next() from the client receive path. Impact: A malicious or compromised authenticated Ceph OSD peer can crash a kernel Ceph client via a malformed sparse-read reply. Reject sparse extent maps that overflow, move backwards, overlap, or extend outside the original sparse-read request before advancing the cursor. [ idryomov: perform sparse_extent_map_valid() check a bit earlier, in CEPH_SPARSE_READ_DATA_LEN instead of CEPH_SPARSE_READ_DATA_PRE state ]
Quoted source text, attributed separately from HOL analysis.