In the Linux kernel, the following vulnerability has been resolved:
ceph: fix num_ops off-by-one when crypto allocation fails
move_dirty_folio_in_page_array() may fail if the file is encrypted, the dirty folio is not the first in the batch, and it fails to allocate a bounce buffer to hold the ciphertext. When that happens, ceph_process_folio_batch() simply redirties the folio and flushes the current batch -- it can retry that folio in a future batch.
However, if this failed folio is not contiguous with the last folio that did make it into the batch, then ceph_process_folio_batch() has already incremented `ceph_wbc->num_ops`; because it doesn't follow through and add the discontiguous folio to the array, ceph_submit_write() -- which expects that `ceph_wbc->num_ops` accurately reflects the number of contiguous ranges (and therefore the required number of "write extent" ops) in the writeback -- will panic the kernel:
BUG_ON(ceph_wbc->op_idx + 1 != req->r_num_ops);
This issue can be reproduced on affected kernels by writing to fscrypt-enabled CephFS file(s) with a 4KiB-written/4KiB-skipped/repeat pattern (total filesize should not matter) and gradually increasing the system's memory pressure until a bounce buffer allocation fails.
Fix this crash by decrementing `ceph_wbc->num_ops` back to the correct value when move_dirty_folio_in_page_array() fails, but the folio already started counting a new (i.e. still-empty) extent.
The defect corrected by this patch has existed since 2022 (see first `Fixes:`), but another bug blocked multi-folio encrypted writeback until recently (see second `Fixes:`). The second commit made it into 6.18.16, 6.19.6, and 7.0-rc1, unmasking the panic in those versions. This patch therefore fixes a regression (panic) introduced by cac190c7674f.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade perf6.18Upgrade python3-perf6.18-debuginfoUpgrade python3-perf6.18Upgrade kernel6.18-debuginfo-common-aarch64Upgrade bpftool6.18Upgrade kernel6.18-tools-debuginfoUpgrade kernel6.18-modules-extra-commonUpgrade kernel6.18-tools-develUpgrade kernel6.18-develUpgrade bpftool6.18-debuginfoUpgrade kernel6.18-debuginfo-common-x86_64Upgrade perf6.18-debuginfoUpgrade kernel6.18-headersUpgrade kernel-livepatch-6.18.30-61.116Upgrade kernel6.18-debuginfoUpgrade kernel6.18-modules-extraUpgrade kernel6.18Upgrade kernel6.18-tools | Jun 23, 2026 | May 27, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 27, 2026 |
| Ubuntu | — | Upgrade linux-image-azure-7.0Upgrade linux-image-oem-26.04aUpgrade linux-image-azureUpgrade linux-image-generic-64kUpgrade linux-image-azure-fdeUpgrade linux-image-7.0.0-1008-oemUpgrade linux-image-realtime-hwe-26.04Upgrade linux-image-raspi-realtime-7.0Upgrade linux-image-oracle-64kUpgrade linux-image-7.0.0-1007-gcpUpgrade linux-image-generic-64k-hwe-26.04Upgrade linux-image-7.0.0-1007-oracle-64kUpgrade linux-image-7.0.0-1013-nvidia-64kUpgrade linux-image-genericUpgrade linux-image-7.0.0-28-generic-64kUpgrade linux-image-gcp-64k-7.0Upgrade linux-image-aws-7.0Upgrade linux-image-realtime-64k-hwe-26.04Upgrade linux-image-oem-7.0Upgrade linux-image-raspiUpgrade linux-image-ibmUpgrade linux-image-7.0.0-1007-oracleUpgrade linux-image-7.0.0-1009-azure-fdeUpgrade linux-image-7.0.0-1009-ibmUpgrade linux-image-realtimeUpgrade linux-image-realtime-64kUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-gcpUpgrade linux-image-7.0.0-27-genericUpgrade linux-image-oem-24.04dUpgrade linux-image-virtual-7.0Upgrade linux-image-oracleUpgrade linux-image-oracle-64k-7.0Upgrade linux-image-oem-24.04bUpgrade linux-image-raspi-7.0Upgrade linux-image-raspi-realtimeUpgrade linux-image-oem-24.04aUpgrade linux-image-aws-64k-7.0Upgrade linux-image-oem-24.04Upgrade linux-image-7.0.0-1008-aws-64kUpgrade linux-image-7.0.0-1010-azureUpgrade linux-image-oracle-7.0Upgrade linux-image-aws-64kUpgrade linux-image-7.0.0-28-genericUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-azure-fde-7.0Upgrade linux-image-virtualUpgrade linux-image-gcp-7.0Upgrade linux-image-realtime-64k-7.0Upgrade linux-image-awsUpgrade linux-image-7.0.0-1008-awsUpgrade linux-image-7.0.0-27-realtimeUpgrade linux-image-7.0.0-1013-nvidiaUpgrade linux-image-generic-64k-7.0Upgrade linux-image-oem-24.04cUpgrade linux-image-generic-7.0Upgrade linux-image-realtime-7.0Upgrade linux-image-nvidia-7.0Upgrade linux-image-nvidia-64k-7.0Upgrade linux-image-7.0.0-1014-raspi-realtimeUpgrade linux-image-7.0.0-1014-raspiUpgrade linux-image-7.0.0-1007-gcp-64kUpgrade linux-image-nvidia-64kUpgrade linux-image-ibm-7.0Upgrade linux-image-generic-hwe-24.04Upgrade linux-image-oem-26.04Upgrade linux-image-7.0.0-27-realtime-64kUpgrade linux-image-7.0.0-27-generic-64kUpgrade linux-image-generic-hwe-26.04Upgrade linux-image-gcp-64kUpgrade linux-image-virtual-hwe-26.04Upgrade linux-image-nvidia | Jul 1, 2026 | May 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub