PatchSiren cyber security CVE debrief
CVE-2026-52961 Linux CVE debrief
A Linux kernel vulnerability was resolved, addressing a BUG_ON in __ceph_build_xattrs_blob() caused by a race condition introduced when moving required_blob_size computation. The issue could lead to a kernel crash. This CVE has a CVSS score of 5.5 and is considered MEDIUM severity. The vulnerability affects Linux kernel developers and administrators responsible for maintaining and securing Linux systems. The bug was introduced in a commit that moved the required_blob_size computation to before the __build_xattrs() call, releasing and reacquiring i_ceph_lock during execution. In that window, handle_cap_grant() may update i_xattrs.blob with a newer MDS-provided blob and bump i_xattrs
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-24
- Original CVE updated
- 2026-09-14
- Advisory published
- 2026-06-24
- Advisory updated
- 2026-09-14
Who should care
Linux kernel developers and administrators responsible for maintaining and securing Linux systems. They should verify their kernel versions and apply patches to prevent potential kernel crashes. They should also monitor system logs for potential exploitation attempts and review compensating controls for exposed systems while remediation is scheduled and verified.
Why it matters
This CVE is considered MEDIUM severity with a CVSS score of 5.5. Linux kernel developers and administrators should verify their kernel versions and apply patches to prevent potential kernel crashes.
- Verify Linux kernel versions to ensure they are not vulnerable
- Apply patches to prevent potential kernel crashes
- Monitor system logs for potential exploitation attempts
Technical summary
The vulnerability is caused by a race condition in the __ceph_build_xattrs_blob() function, which can lead to a kernel crash. The issue was introduced when moving required_blob_size computation to before the __build_xattrs() call. The bug was fixed in a later commit. The vulnerability affects Linux kernel developers and administrators responsible for maintaining and securing Linux systems. The CVE has a CVSS score of 5.5 and is considered MEDIUM severity. The vulnerability can be mitigated by applying patches and reviewing and updating Linux kernel versions.
Defensive priority
Apply patches to prevent potential kernel crashes
Recommended defensive actions
- Apply patches to prevent potential kernel crashes
- Review and update Linux kernel versions to ensure they are not vulnerable
- Monitor system logs for potential exploitation attempts
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, including its description, CVSS score, and affected versions. The generic/642 test-case can reproduce the kernel crash. The vulnerability was introduced in commit d93231a6bc8a (ceph: prevent a client from exceeding the MDS maximum xattr size). The bug was fixed in a later commit. Linux kernel developers and administrators should verify their kernel versions and apply patches to prevent potential kernel crashes.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-52961 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-52961
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-52961 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52961
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0c22d9511cbde746622f8e4c11aaa63fe76d45f9
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/368d21ae9081c93497b1c8163bed3eddcb2443ff
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7eb72425c4e3234926502eb262f9d6193ccd572c
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d161c4456672f8c431e3bdf9bea817b490d14181
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d5bd8b4e39cfa8b087448adcd48088065cd629d5
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.