External risk intelligence

Linux Kernel Ceph xattr Value Length Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-89649

The vulnerability exists within the Linux kernel's Ceph filesystem client handling of xattr data. Exploitation requires a compromised or malicious metadata server and is triggered by a local user executing a getxattr system call on a mounted CephFS file. This is an internal, local-operation vulnerability not exposed to the public internet.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the Linux kernel's Ceph file system could allow a malicious metadata server to disclose adjacent kernel heap bytes to a local user. This occurs when a specific attribute's value length is incorrectly handled, leading to an out-of-bounds read. The issue has been resolved by adding a check to ensure the value length does not exceed the available data within the blob.

  • Kernel code flaw exposes sensitive data.
  • Matters for data security and integrity.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker with control over a Ceph metadata server could craft a special attribute that, when read by a local user through the `getxattr` system call, exposes adjacent kernel memory. This occurs because the Linux kernel's Ceph component in `__build_xattrs()` doesn't properly check the bounds of the final attribute's value length, allowing it to exceed the allocated buffer.

  • Requires a compromised metadata server.
  • Triggered by a local user's `getxattr` call.
  • Discloses sensitive kernel memory.

Live Threat

Current exploitation, exposure, and threat context

A malicious or compromised metadata server could disclose adjacent kernel heap bytes to a local user. This could happen when a local user performs a `getxattr(2)` operation on a CephFS file. The vulnerability involves an unchecked value length in the final attribute of an xattr blob, potentially allowing an attacker to read beyond the allocated buffer.

  • Kernel heap data at risk.
  • Malicious metadata server, local user trigger.
  • Disclosure of adjacent kernel memory.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts the Linux kernel's handling of extended attributes within the Ceph filesystem. Responsibility for remediation likely falls to teams managing the Ceph infrastructure and the Linux kernel instances where CephFS is deployed, potentially including platform or storage administrators. The immediate first step is to confirm the presence of vulnerable CephFS deployments, assess their exposure and criticality, and then coordinate with relevant teams and potentially vendors to plan a fix.

  • Identify CephFS deployments and owners.
  • Verify user-accessible CephFS file systems.
  • Plan vendor coordination and kernel updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel Ceph file system component?

CephFS is a distributed file system that allows multiple clients to access data stored on a cluster of servers. The Linux kernel includes a Ceph client module that enables your operating system to mount and interact with these distributed volumes as if they were local storage. This specific vulnerability affects how the kernel client parses extended attributes, or xattrs, which are metadata tags stored alongside files to provide extra information like permissions or custom properties.

What is the weakness class behind CVE-2026-89649?

This vulnerability is an out-of-bounds read error. It occurs because the kernel code fails to verify that the length of the final extended attribute in a data packet matches the actual size of the available memory buffer. Because the system does not perform a bounds check on this last attribute, it may inadvertently read and return data from memory addresses immediately following the intended buffer, which could contain sensitive information from other parts of the kernel heap.

How is this memory disclosure bug triggered?

An attacker must control or compromise a Ceph metadata server to send a malformed attribute blob to the client. The bug is specifically triggered when a local user on the client machine executes a getxattr system call on a file stored in the affected CephFS mount. If the metadata server sends an attribute with a falsified length, the kernel will attempt to copy more data than exists, returning adjacent memory. Standard file operations that do not involve reading attributes remain unaffected.

Is this CVE reachable from the public internet?

According to Halo Surface Signal, this vulnerability is considered very unlikely to be exposed via the internet. It requires a specific, multi-stage path involving a compromised internal metadata server and a local user interaction on the client system. Because the trigger relies on internal Ceph protocol communication and a local system call, it is classified as an internal, local-operation vulnerability rather than a direct remote network target.

How should I respond to CVE-2026-89649?

Begin by identifying all systems in your environment that mount CephFS volumes. Once these assets are mapped, coordinate with your infrastructure or platform administrators to review the kernel versions currently running on those clients. Since this is a core kernel issue, remediation involves planning a software update to a patched kernel version provided by your operating system vendor or distribution maintainers to ensure the missing memory safety check is applied.

References