External risk intelligence

Linux Kernel Ceph NFS Export Name Overflow

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-89652

The vulnerability is located deep within the Linux kernel's CephFS client implementation, specifically triggered only when a CephFS mount is re-exported over NFS. This is a specialized configuration requiring internal infrastructure components to be chained, making public internet exposure of the vulnerable interface uncommon.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a vulnerability in the Linux kernel's CephFS implementation that could be triggered when CephFS is re-exported over NFS. An attacker could potentially exploit this by sending malformed data, leading to a buffer overflow and a system crash or unpredictable behavior. The main concern is confirming relevance and exposure given the specific conditions required for exploitation.

  • Overflows in file name handling in CephFS.
  • Critical flaw impacting system stability if exploited.
  • Confirm if your NFS re-exports of CephFS are affected.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this by manipulating a Ceph Metadata Server (MDS) to send an excessively long file name during a lookup. This crafted name would overflow a buffer in the client's NFS export handling, leading to a crash.

  • Entry condition: A CephFS mount re-exported over NFS.
  • Trigger point: A malicious MDS providing a long name.
  • Resulting risk: Out-of-bounds write, potential system crash.

Live Threat

Current exploitation, exposure, and threat context

When a CephFS mount is re-exported over NFS, a malicious or compromised Ceph MDS could overflow a buffer on the NFS client. This could lead to an out-of-bounds write in the kernel when copying a file name, potentially impacting system stability.

  • Kernel memory corruption.
  • Malicious MDS supplies oversized name.
  • System instability or crash.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts systems where CephFS is re-exported over NFS, pointing to potential ownership by infrastructure, platform, or storage teams responsible for managing Ceph and NFS services. The immediate priority is to identify all instances of this specific configuration, confirm business criticality and external reachability, and assign an accountable owner before planning remediation.

  • Infrastructure and platform teams own the issue.
  • Verify CephFS NFS re-export configurations.
  • Plan remediation based on exposure and criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the CephFS component affected by CVE-2026-89652?

CephFS is a distributed file system that allows multiple clients to access data stored across a cluster. This vulnerability specifically exists in the Linux kernel's Ceph client code, which handles communication between the operating system and the Ceph storage cluster. It concerns how the client interprets file names provided by the Metadata Server (MDS), a central component responsible for managing the file system hierarchy and metadata.

How does CVE-2026-89652 work as a buffer overflow?

This vulnerability is an out-of-bounds write. When the kernel client asks the Metadata Server for a file name, it places that name into a fixed-size memory buffer. The vulnerability occurs because the software fails to verify if the incoming name exceeds the maximum allowed length before copying it. If the server provides a name that is too large, the extra data spills over into adjacent memory, which can corrupt the system's internal state.

What specific actions trigger this kernel vulnerability?

The flaw is triggered specifically when a CephFS mount is re-exported to other machines over NFS. It requires the Linux kernel to perform a name lookup during these NFS operations. Simply using CephFS directly on a client without the NFS re-export layer does not trigger this specific code path. The trigger requires the system to act as a gateway that shares Ceph storage files via the NFS protocol.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal labels this as unlikely for most because the vulnerability is deep within specialized infrastructure. It only impacts systems configured as NFS gateways for CephFS. Because this requires chaining specific internal storage components together, it is rarely exposed directly to the public internet, though you should verify your internal network architecture for this unique configuration.

What is the first step for teams managing this technology?

Infrastructure and storage teams should begin by auditing their environment to locate any instances where CephFS mounts are being re-exported via NFS. Once identified, confirm if these systems are running the vulnerable kernel code. The goal is to prioritize these specific servers for updates to ensure the input length check is properly implemented before any malicious Metadata Server can interact with them.

References