ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
authorJérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Thu, 13 Aug 2026 12:00:00 +0000 (14:00 +0200)
committerIlya Dryomov <idryomov@gmail.com>
Wed, 26 Aug 2026 17:57:29 +0000 (19:57 +0200)
commitaedc9053d909508a5f56c3f49f885fc030df4730
tree8cb088c4ac4906145653a9a1f415931339ead2f2
parentc25aee9c630fb86f98d79eccb75765067079b972
ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode

MDSMap export_targets entries are monitor controlled. check_new_map()
uses each entry as a bit number in a fixed stack bitmap, so a rank
outside the protocol namespace can make set_bit() write past the end of
the array.

Reject ranks outside CEPH_MAX_MDS while decoding the map. Do not
validate against possible_max_rank here because maps may legitimately
reference ranks beyond a temporarily reduced max_mds.

Cc: stable@vger.kernel.org
Fixes: d517b3983dd3 ("ceph: reconnect to the export targets on new mdsmaps")
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Reviewed-by: Alex Markuze <amarkuze@redhat.com>
Signed-off-by: Alex Markuze <amarkuze@redhat.com>
Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
fs/ceph/mdsmap.c