CVE-2026-23201
published 2026-02-14CVE-2026-23201: In the Linux kernel, the following vulnerability has been resolved: ceph: fix oops due to invalid pointer for kfree() in parse_longname() This fixes a kernel…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix oops due to invalid pointer for kfree() in parse_longname()
This fixes a kernel oops when reading ceph snapshot directories (.snap),
for example by simply running `ls /mnt/my_ceph/.snap`.
The variable str is guarded by __free(kfree), but advanced by one for
skipping the initial '_' in snapshot names. Thus, kfree() is called
with an invalid pointer. This patch removes the need for advancing the
pointer so kfree() is called with correct memory pointer.
Steps to reproduce:
1. Create snapshots on a cephfs volume (I've 63 snaps in my testcase)
2. Add cephfs mount to fstab
$ echo "[email protected]=/volumes/datapool/stuff/3461082b-ecc9-4e82-8549-3fd2590d3fb6 /mnt/test/stuff ceph acl,noatime,_netdev 0 0" >> /etc/fstab
3. Reboot the system
$ systemctl reboot
4. Check if it's really mounted
$ mount | grep stuff
5. List snapshots (expected 63 snapshots on my system)
$ ls /mnt/test/stuff/.snap
Now ls hangs forever and the kernel log shows the oops.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.18.10-1 (forky) | linux 6.18.10-1 (forky) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 101841c38346f4ca41dc1802c867da990ffb32eb < e258ed369c9e04caa7d2fd49785d753ae4034cb6 | e258ed369c9e04caa7d2fd49785d753ae4034cb6 |
| linux | linux | >= 101841c38346f4ca41dc1802c867da990ffb32eb < bc8dedae022ce3058659c3addef3ec4b41d15e00 | bc8dedae022ce3058659c3addef3ec4b41d15e00 |
| linux | linux | >= 6.12.42 < 6.12.70 | 6.12.70 |
| linux | linux | >= 6.15.10 < 6.16 | 6.16 |
| linux | linux | >= 6.16.1 < 6.17 | 6.17 |
| linux | linux | >= bb80f7618832d26f7e395f52f82b1dac76223e5f < 8c9af7339de419819cfc641d551675d38ff99abf | 8c9af7339de419819cfc641d551675d38ff99abf |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.12.73-1 | 6.12.73-1 |
| linux | linux_kernel | >= 0 < 6.18.10-1 | 6.18.10-1 |
| linux | linux_kernel | >= 6.12.42 < 6.12.70 | 6.12.70 |
| linux | linux_kernel | >= 6.15.10 < 6.16 | 6.16 |
| linux | linux_kernel | >= 6.16.1 < 6.18.10 | 6.18.10 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.12.69/6.18.9 ceph kfree denial of service (EUVD-2026-5844 / Nessus ID 299103)
vuldb·2026-05-24·CVSS 5.5
CVE-2026-23201 [MEDIUM] Linux Kernel up to 6.12.69/6.18.9 ceph kfree denial of service (EUVD-2026-5844 / Nessus ID 299103)
A vulnerability has been found in Linux Kernel up to 6.12.69/6.18.9 and classified as critical. Affected by this issue is the function kfree of the component ceph. Performing a manipulation results in denial of service.
This vulnerability was named CVE-2026-23201. The attack needs to be approached within the local network. There is no available exploit.
The affected component should be upgraded.
GHSA
GHSA-3mg9-9f72-h562: In the Linux kernel, the following vulnerability has been resolved:
ceph: fix oops due to invalid pointer for kfree() in parse_longname()
This fixes
ghsa_unreviewed·2026-02-14
CVE-2026-23201 [MEDIUM] CWE-476 GHSA-3mg9-9f72-h562: In the Linux kernel, the following vulnerability has been resolved:
ceph: fix oops due to invalid pointer for kfree() in parse_longname()
This fixes
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix oops due to invalid pointer for kfree() in parse_longname()
This fixes a kernel oops when reading ceph snapshot directories (.snap),
for example by simply running `ls /mnt/my_ceph/.snap`.
The variable str is guarded by __free(kfree), but advanced by one for
skipping the initial '_' in snapshot names. Thus, kfree() is called
with an invalid pointer. This patch removes the need for advancing the
pointer so kfree() is called with correct memory pointer.
Steps to reproduce:
1. Create snapshots on a cephfs volume (I've 63 snaps in my testcase)
2. Add cephfs mount to fstab
$ echo "[email protected]=/volumes/datapool/stuff/3461082b-ecc9-4e82-8549-3fd2590d3fb6 /mnt/test/stuff ceph acl,noatime,_netdev 0 0" >>
OSV
CVE-2026-23201: In the Linux kernel, the following vulnerability has been resolved: ceph: fix oops due to invalid pointer for kfree() in parse_longname() This fixes a
osv·2026-02-14·CVSS 5.5
CVE-2026-23201 [MEDIUM] CVE-2026-23201: In the Linux kernel, the following vulnerability has been resolved: ceph: fix oops due to invalid pointer for kfree() in parse_longname() This fixes a
In the Linux kernel, the following vulnerability has been resolved: ceph: fix oops due to invalid pointer for kfree() in parse_longname() This fixes a kernel oops when reading ceph snapshot directories (.snap), for example by simply running `ls /mnt/my_ceph/.snap`. The variable str is guarded by __free(kfree), but advanced by one for skipping the initial '_' in snapshot names. Thus, kfree() is called with an invalid pointer. This patch removes the need for advancing the pointer so kfree() is called with correct memory pointer. Steps to reproduce: 1. Create snapshots on a cephfs volume (I've 63 snaps in my testcase) 2. Add cephfs mount to fstab $ echo "[email protected]=/volumes/datapool/stuff/3461082b-ecc9-4e82-8549-3fd2590d3fb6 /mnt/test/stuff ceph acl,noatime,_netdev 0 0" >> /etc/f
Red Hat
kernel: ceph: fix oops due to invalid pointer for kfree() in parse_longname()
vendor_redhat·2026-02-14·CVSS 5.5
CVE-2026-23201 [MEDIUM] kernel: ceph: fix oops due to invalid pointer for kfree() in parse_longname()
kernel: ceph: fix oops due to invalid pointer for kfree() in parse_longname()
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix oops due to invalid pointer for kfree() in parse_longname()
This fixes a kernel oops when reading ceph snapshot directories (.snap),
for example by simply running `ls /mnt/my_ceph/.snap`.
The variable str is guarded by __free(kfree), but advanced by one for
skipping the initial '_' in snapshot names. Thus, kfree() is called
with an invalid pointer. This patch removes the need for advancing the
pointer so kfree() is called with correct memory pointer.
Steps to reproduce:
1. Create snapshots on a cephfs volume (I've 63 snaps in my testcase)
2. Add cephfs mount to fstab
$ echo "[email protected]=/volumes/datapool/stuff/3461082b-ecc9
Debian
CVE-2026-23201: linux - In the Linux kernel, the following vulnerability has been resolved: ceph: fix o...
vendor_debian·2026·CVSS 5.5
CVE-2026-23201 [MEDIUM] CVE-2026-23201: linux - In the Linux kernel, the following vulnerability has been resolved: ceph: fix o...
In the Linux kernel, the following vulnerability has been resolved: ceph: fix oops due to invalid pointer for kfree() in parse_longname() This fixes a kernel oops when reading ceph snapshot directories (.snap), for example by simply running `ls /mnt/my_ceph/.snap`. The variable str is guarded by __free(kfree), but advanced by one for skipping the initial '_' in snapshot names. Thus, kfree() is called with an invalid pointer. This patch removes the need for advancing the pointer so kfree() is called with correct memory pointer. Steps to reproduce: 1. Create snapshots on a cephfs volume (I've 63 snaps in my testcase) 2. Add cephfs mount to fstab $ echo "[email protected]=/volumes/datapool/stuff/3461082b-ecc9-4e82-8549-3fd2590d3fb6 /mnt/test/stuff ceph acl,noatime,_netdev 0 0" >> /etc/f
No detection rules found.
No public exploits indexed.
2026-02-14
Published