PT-2025-51578 · Linux+4 · Linux Kernel+4

Published

2025-09-11

·

Updated

2026-05-26

·

CVE-2025-40362

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw in the Ceph implementation related to MultiFS MDS authentication capabilities. Specifically, the check for authentication capabilities does not validate the filesystem name (fsname) alongside the associated capabilities. This allows the application of authentication capabilities from one filesystem to another within a multi-filesystem Ceph cluster. This can lead to unauthorized access, allowing users to perform actions on filesystems where they should not have permissions, such as creating, deleting, or modifying files. The issue occurs when mounting filesystems with specific user permissions, potentially allowing a user with read-only access to one filesystem to gain read-write access to another. The problem is reproducible using the ceph command-line tool and involves authorizing permissions for a user on multiple filesystems and then attempting to perform unauthorized actions. The vulnerability impacts user authentication within a Ceph cluster.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03005
CVE-2025-40362
ECHO-C77E-F752-503E
OPENSUSE-SU-2026:20145-1
SUSE-SU-2026:20207-1
SUSE-SU-2026:20220-1
SUSE-SU-2026:20228-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1

Affected Products

Ceph
Debian
Linuxmint
Linux Kernel
Ubuntu