CVE-2026-68153
Detail
Received
This CVE record has recently been published to the CVE List and has been included within the NVD dataset.
Description
In the Linux kernel, the following vulnerability has been resolved:
libceph: remove debugfs files before client teardown
ceph_destroy_client() tears down the monitor client before removing
the per-client debugfs files. A concurrent read of the monmap debugfs
file can enter monmap_show() after ceph_monc_stop() has freed
monc->monmap, triggering a use-after-free.
Remove the debugfs files before stopping the OSD and monitor clients.
debugfs_remove() drains active handlers and prevents new accesses, so
the debugfs callbacks can no longer race the rest of client teardown.
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 4.0 Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 3.x Severity and Vector Strings:
NVD assessment
not yet provided.
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.0 Severity and Vector Strings:
NVD assessment
not yet provided.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected] .
Change History
4 change records found show changes
CVE Modified by kernel.org
8/19/2026 1:20:32 PM
Action
Type
Old Value
New Value
Added
Reference
https://git.kernel.org/stable/c/463a264e9094384112a5c8b46f0a9ddaf8566904
Added
Reference
https://git.kernel.org/stable/c/ac78549d186090ee7125d28c3a8c376573b36194
Added
Reference
https://git.kernel.org/stable/c/fe46b7e06f14f6f94766832df309b249cb689d27
Changed
Affected
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ceph/ceph_common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"fc1010e7e0204ece6cc0f9af4f473e9553535eab","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"d3dc8889d39a676bf840132bd5c5c48cb0daba23","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"8f5a3abc54ba24dbceb14cc3a719908c4f688091","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"b9fedda2f628e030384228de0dafc574b7fb0c2f","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"e4c804726c4afce3ba648b982d564f6af2cfa328","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ceph/ceph_common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.34","status":"affected"},{"version":"0","lessThan":"2.6.34","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]
Record truncated, showing 2048 of 2461 characters.
View Entire Change Record
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ceph/ceph_common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"ac78549d186090ee7125d28c3a8c376573b36194","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"463a264e9094384112a5c8b46f0a9ddaf8566904","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"fe46b7e06f14f6f94766832df309b249cb689d27","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"fc1010e7e0204ece6cc0f9af4f473e9553535eab","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"d3dc8889d39a676bf840132bd5c5c48cb0daba23","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"8f5a3abc54ba24dbceb14cc3a719908c4f688091","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"b9fedda2f628e030384228de0dafc574b7fb0c2f","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"e4c804726c4afce3ba648b982d564f6af2cfa328","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ceph/ceph_common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.34","status":"affected"},{"version":"0","lessThan":"2.6.34","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"se
CVE Modified by kernel.org
8/17/2026 1:18:15 AM
Action
Type
Old Value
New Value
Changed
Affected
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ceph/ceph_common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"fc1010e7e0204ece6cc0f9af4f473e9553535eab","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"d3dc8889d39a676bf840132bd5c5c48cb0daba23","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"8f5a3abc54ba24dbceb14cc3a719908c4f688091","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"b9fedda2f628e030384228de0dafc574b7fb0c2f","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"e4c804726c4afce3ba648b982d564f6af2cfa328","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ceph/ceph_common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.34","status":"affected"},{"version":"0","lessThan":"2.6.34","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc5","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ceph/ceph_common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"fc1010e7e0204ece6cc0f9af4f473e9553535eab","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"d3dc8889d39a676bf840132bd5c5c48cb0daba23","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"8f5a3abc54ba24dbceb14cc3a719908c4f688091","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"b9fedda2f628e030384228de0dafc574b7fb0c2f","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"e4c804726c4afce3ba648b982d564f6af2cfa328","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ceph/ceph_common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.34","status":"affected"},{"version":"0","lessThan":"2.6.34","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]
CVE Modified by kernel.org
8/13/2026 7:17:20 PM
Action
Type
Old Value
New Value
Added
CVSS V3.1
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
New CVE Received from kernel.org
8/10/2026 9:20:01 AM
Action
Type
Old Value
New Value
Added
Description
In the Linux kernel, the following vulnerability has been resolved:
libceph: remove debugfs files before client teardown
ceph_destroy_client() tears down the monitor client before removing
the per-client debugfs files. A concurrent read of the monmap debugfs
file can enter monmap_show() after ceph_monc_stop() has freed
monc->monmap, triggering a use-after-free.
Remove the debugfs files before stopping the OSD and monitor clients.
debugfs_remove() drains active handlers and prevents new accesses, so
the debugfs callbacks can no longer race the rest of client teardown.
Added
Reference
https://git.kernel.org/stable/c/8f5a3abc54ba24dbceb14cc3a719908c4f688091
Added
Reference
https://git.kernel.org/stable/c/b9fedda2f628e030384228de0dafc574b7fb0c2f
Added
Reference
https://git.kernel.org/stable/c/d3dc8889d39a676bf840132bd5c5c48cb0daba23
Added
Reference
https://git.kernel.org/stable/c/e4c804726c4afce3ba648b982d564f6af2cfa328
Added
Reference
https://git.kernel.org/stable/c/fc1010e7e0204ece6cc0f9af4f473e9553535eab
Added
Affected
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ceph/ceph_common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"fc1010e7e0204ece6cc0f9af4f473e9553535eab","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"d3dc8889d39a676bf840132bd5c5c48cb0daba23","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"8f5a3abc54ba24dbceb14cc3a719908c4f688091","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"b9fedda2f628e030384228de0dafc574b7fb0c2f","versionType":"git","status":"affected"},{"version":"76aa844d5b2fb8c839180d3f5874e333b297e5fd","lessThan":"e4c804726c4afce3ba648b982d564f6af2cfa328","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ceph/ceph_common.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.34","status":"affected"},{"version":"0","lessThan":"2.6.34","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc5","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]
Quick Info
CVE Dictionary Entry: CVE-2026-68153 NVD
Published Date: 08/10/2026 NVD
Last Modified: 08/19/2026
Source: kernel.org