CVE-2026-68153EPSS p6.4%
CVE-2026-68153CVE-2026-68153
Description
In the Linux kernel, the following vulnerability has been resolved:
libceph: remove debugfs files before client teardown
ceph_destroy_client() tears down the monitor client before removing
the per-client debugfs files. A concurrent read of the monmap debugfs
file can enter monmap_show() after ceph_monc_stop() has freed
monc->monmap, triggering a use-after-free.
Remove the debugfs files before stopping the OSD and monitor clients.
debugfs_remove() drains active handlers and prevents new accesses, so
the debugfs callbacks can no longer race the rest of client teardown.
Scoring
| EPSS | 0.17% probability of exploitation · percentile 6.4% · 2026-08-11T12:00:17Z |
| Last modified | 2026-08-10 |