CVE-2026-89656
A malformed CRUSH map can cause the Linux kernel’s libceph code to write four bytes beyond an allocated workspace, potentially affecting data confidentiality, integrity, and availability. The vulnerability is rated critical at 9.8 and can be triggered over the network without prior authentication or user interaction.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
No affected products are listed in the supplied CPE data.
Real-world impact
The flaw may allow an out-of-bounds write in the kernel’s CRUSH mapping code, which could disrupt the system or compromise stored information.
Why this severity
Critical (CVSS 3.1 score: 9.8)
What to do about it
- 01Upgrade the Linux kernel to a release that includes the resolved fix titled “libceph: reject buckets with mismatched CRUSH ids.”
NVD states that the Linux kernel vulnerability has been resolved and describes the fix as “libceph: reject buckets with mismatched CRUSH ids.” No fixed version number is provided in the supplied data.
Timeline
- Sep 11, 2026 · 2d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 13, 2026 · 8h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.