PT-2025-51578 · Linux+4 · Linux Kernel+4
Published
2025-09-11
·
Updated
2026-05-26
·
CVE-2025-40362
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains a flaw in the Ceph implementation related to MultiFS MDS authentication capabilities. Specifically, the check for authentication capabilities does not validate the filesystem name (
fsname) alongside the associated capabilities. This allows the application of authentication capabilities from one filesystem to another within a multi-filesystem Ceph cluster. This can lead to unauthorized access, allowing users to perform actions on filesystems where they should not have permissions, such as creating, deleting, or modifying files. The issue occurs when mounting filesystems with specific user permissions, potentially allowing a user with read-only access to one filesystem to gain read-write access to another. The problem is reproducible using the ceph command-line tool and involves authorizing permissions for a user on multiple filesystems and then attempting to perform unauthorized actions. The vulnerability impacts user authentication within a Ceph cluster.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ceph
Debian
Linuxmint
Linux Kernel
Ubuntu