Linux vulnerability

In the Linux kernel, the following vulnerability has been resolved: [ceph] parse_longname(): strrchr() expects NUL-terminated string ... and parse_longname() is not guaranteed that. That's the reason why it uses kmemdup_nul() to build the argument for kstrtou64(); the problem is, kstrtou64() is not the only thing that need it. Just get a NUL-terminated copy of the entire thing and be done with that...

Published 22 Aug 2025Updated 14 Sep 20265 sources
CVSS 9.8

What happened

In the Linux kernel, the following vulnerability has been resolved: [ceph] parse_longname(): strrchr() expects NUL-terminated string ... and parse_longname() is not guaranteed that. That's the reason why it uses kmemdup_nul() to build the argument for kstrtou64(); the problem is, kstrtou64() is not the only thing that need it. Just get a NUL-terminated copy of the entire thing and be done with that...

Affected versions

Linux: dd66df0053ef84add5e684df517aa9b498342381 through before 4b9aee707c4580511983a0998547f3b28514e6a6 (git); dd66df0053ef84add5e684df517aa9b498342381 through before bb80f7618832d26f7e395f52f82b1dac76223e5f (git); dd66df0053ef84add5e684df517aa9b498342381 through before 3145b2b11492d61c512bbc59660bb823bc757f48 (git); dd66df0053ef84add5e684df517aa9b498342381 through before 493479af8af3ab907f49e99323777d498a4fbd2b (git); dd66df0053ef84add5e684df517aa9b498342381 through before 101841c38346f4ca41dc1802c867da990ffb32eb (git); 6.6 Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.