Kernel-level RCE in libceph impacts Ceph storage stacks used widely across enterprises and cloud providers; can lead to host/storage compromise and service disruption.
CVE-2026-89656
Linux kernel libceph CRUSH parsing OOB write enabling potential RCE (CVE-2026-89656).
Is CVE-2026-89656 being exploited?
Not confirmed. CVE-2026-89656 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.52% probability of exploitation in the next 30 days.
How severe is CVE-2026-89656?
CVE-2026-89656 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-89656?
Yes. A fix has been recorded for CVE-2026-89656. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-89656 affect?
CVE-2026-89656 affects Linux kernel (libceph CRUSH parsing), Ceph storage deployments (clients/monitors/OSDs), Systems using kernel CRUSH maps. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-89656?
Apply kernel updates with libceph CRUSH fix immediately; restrict Ceph map access and audit clusters.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Out-of-bounds write during CRUSH map parsing can lead to kernel memory corruption and remote code execution, enabling host compromise and storage disruption.
Immediate action required
- affected>= 66a0e2d579dbec5c676cfe446234ffebb267c564 and < 3516a4131c4e45d62ee4e42e82c36930e8c1fbbd
- affected>= 66a0e2d579dbec5c676cfe446234ffebb267c564 and < 00562ccd4e88d092b9b851df50fad20442bfeb24
- affected>= 66a0e2d579dbec5c676cfe446234ffebb267c564 and < 79900d978158b2d80eef952fc41b9e4dc58d7b83
- affected>= 66a0e2d579dbec5c676cfe446234ffebb267c564 and < 3cde4a8302301679937474a5f7a851394cc1bd11
- affected4.11
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.