Kernel-level Ceph vulnerability with 9.8 CVSS affecting Linux kernels and Ceph deployments; can allow kernel compromise across enterprise storage/servers.
CVE-2026-89653
Linux kernel Ceph MDS map OOB write leading to kernel memory corruption
Is CVE-2026-89653 being exploited?
Not confirmed. CVE-2026-89653 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.51% probability of exploitation in the next 30 days.
How severe is CVE-2026-89653?
CVE-2026-89653 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-89653?
Yes. A fix has been recorded for CVE-2026-89653. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-89653 affect?
CVE-2026-89653 affects Linux kernel (Ceph mdsmap decoding), Ceph storage deployments, Kernels with built-in Ceph support. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-89653?
Apply vendor kernel updates or backported Ceph patches immediately; restrict monitor/MDS access.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Out-of-bounds kernel write via malformed Ceph MDS map; can cause kernel memory corruption, crashes, or privilege escalation to root.
Immediate action required
- affected>= d517b3983dd3106ca92d6c5d0d09415a4a09481c and < 736adee11af36e407ed902264f8b2fb5cf94b62f
- affected>= d517b3983dd3106ca92d6c5d0d09415a4a09481c and < 4d298880f82c42383b36946bafde7ccf4d804c9b
- affected>= d517b3983dd3106ca92d6c5d0d09415a4a09481c and < 96c3f5fbb0d5386e7111426f047f98cec4586674
- affected>= d517b3983dd3106ca92d6c5d0d09415a4a09481c and < aedc9053d909508a5f56c3f49f885fc030df4730
- affected5.15
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.