CVE-2026-52958 (GCVE-0-2026-52958)
Vulnerability from cvelistv5
Published
2026-06-24 16:28
Modified
2026-08-05 12:32
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdmap_decode() When decoding osd_state and osd_weight from an incoming osdmap in osdmap_decode(), both are decoded for each osd, i.e., map->max_osd times. The ceph_decode_need() check only accounts for sizeof(*map->osd_weight) once. This can potentially result in an out-of-bounds memory access if the incoming message is corrupted such that the max_osd value exceeds the actual content of the osdmap message. This patch fixes the issue by changing the corresponding part in the ceph_decode_need() check to account for map->max_osd*sizeof(*map->osd_weight).
Impacted products
Vendor Product Version
Linux Linux Version: dcbc919a5dc8c2629684a113a90c0b6fe10c3462
Version: dcbc919a5dc8c2629684a113a90c0b6fe10c3462
Version: dcbc919a5dc8c2629684a113a90c0b6fe10c3462
Version: dcbc919a5dc8c2629684a113a90c0b6fe10c3462
Version: dcbc919a5dc8c2629684a113a90c0b6fe10c3462
Version: dcbc919a5dc8c2629684a113a90c0b6fe10c3462
Version: dcbc919a5dc8c2629684a113a90c0b6fe10c3462
Version: dcbc919a5dc8c2629684a113a90c0b6fe10c3462
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/ceph/osdmap.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "36a79759a288961b1ff28a68ec2d1f56f6848098",
              "status": "affected",
              "version": "dcbc919a5dc8c2629684a113a90c0b6fe10c3462",
              "versionType": "git"
            },
            {
              "lessThan": "3f2575bb7f955d42569d96c3e04fa958a0dcf4b4",
              "status": "affected",
              "version": "dcbc919a5dc8c2629684a113a90c0b6fe10c3462",
              "versionType": "git"
            },
            {
              "lessThan": "8713bbc4b2b9ad78f803978e54b7e49dd21bd9be",
              "status": "affected",
              "version": "dcbc919a5dc8c2629684a113a90c0b6fe10c3462",
              "versionType": "git"
            },
            {
              "lessThan": "0d2dd7e6bb74fd7712aa73457a4a821906c6863a",
              "status": "affected",
              "version": "dcbc919a5dc8c2629684a113a90c0b6fe10c3462",
              "versionType": "git"
            },
            {
              "lessThan": "e7187f33c02488697ec0d01d82bf7a3f8deaba8f",
              "status": "affected",
              "version": "dcbc919a5dc8c2629684a113a90c0b6fe10c3462",
              "versionType": "git"
            },
            {
              "lessThan": "48df98d12b15360cd56af5c1f460307b340c1197",
              "status": "affected",
              "version": "dcbc919a5dc8c2629684a113a90c0b6fe10c3462",
              "versionType": "git"
            },
            {
              "lessThan": "ee933694645dac062d65fc2743f92bc06fa0db6b",
              "status": "affected",
              "version": "dcbc919a5dc8c2629684a113a90c0b6fe10c3462",
              "versionType": "git"
            },
            {
              "lessThan": "35d0ed82d03e5ee77ea4f31f20e29562a7721649",
              "status": "affected",
              "version": "dcbc919a5dc8c2629684a113a90c0b6fe10c3462",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/ceph/osdmap.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.3"
            },
            {
              "lessThan": "5.3",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.258",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.209",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.175",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.141",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.91",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.33",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.0.*",
              "status": "unaffected",
              "version": "7.0.10",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.258",
                  "versionStartIncluding": "5.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.209",
                  "versionStartIncluding": "5.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.175",
                  "versionStartIncluding": "5.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.141",
                  "versionStartIncluding": "5.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.91",
                  "versionStartIncluding": "5.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.33",
                  "versionStartIncluding": "5.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0.10",
                  "versionStartIncluding": "5.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1",
                  "versionStartIncluding": "5.3",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Fix potential out-of-bounds access in osdmap_decode()\n\nWhen decoding osd_state and osd_weight from an incoming osdmap in\nosdmap_decode(), both are decoded for each osd, i.e., map-\u003emax_osd\ntimes. The ceph_decode_need() check only accounts for\nsizeof(*map-\u003eosd_weight) once. This can potentially result in an\nout-of-bounds memory access if the incoming message is corrupted such\nthat the max_osd value exceeds the actual content of the osdmap message.\n\nThis patch fixes the issue by changing the corresponding part in the\nceph_decode_need() check to account for\nmap-\u003emax_osd*sizeof(*map-\u003eosd_weight)."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The vulnerable decoder processes Ceph OSD map messages received over Ceph messenger connections from monitors or OSDs. A malicious or compromised network Ceph peer can deliver the crafted map to a connected kernel client.\nAC:L - The trigger is a deterministic malformed OSD map with `max_osd` larger than the supplied `osd_weight` content. No race or condition outside the attacker\u0027s control is required.\nPR:N - The attacker does not need privileges on the vulnerable Linux system; the crafted data is supplied by a remote Ceph peer. Ceph also supports auth-none deployments, so the highest defensible scenario does not require authenticated attacker privileges.\nUI:N - Once the kernel Ceph client is connected, OSD map updates are processed asynchronously without a user action. The attacker can trigger parsing by sending the crafted map over the established network connection.\nS:U - The impact is within the kernel/client system that parses the malicious Ceph message. This is not a VM escape, IOMMU bypass, or other cross-scope boundary change.\nC:H - The bug is an out-of-bounds read from the received message buffer, and the read can extend beyond a small bounded area based on attacker-controlled `max_osd`. Following the higher-severity rule for OOB reads, this supports high confidentiality impact.\nI:N - The faulty loop reads past the input buffer into the allocated `osd_weight` array but does not write out of bounds or provide a clear kernel memory write primitive. The malformed full map is rejected after decoding fails.\nA:H - The out-of-bounds kernel read can fault or otherwise crash the kernel when it crosses invalid memory, and malformed OSD maps can be sent repeatedly by the network peer. Kernel crash or oops is high availability impact."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:32:08.518Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/36a79759a288961b1ff28a68ec2d1f56f6848098"
        },
        {
          "url": "https://git.kernel.org/stable/c/3f2575bb7f955d42569d96c3e04fa958a0dcf4b4"
        },
        {
          "url": "https://git.kernel.org/stable/c/8713bbc4b2b9ad78f803978e54b7e49dd21bd9be"
        },
        {
          "url": "https://git.kernel.org/stable/c/0d2dd7e6bb74fd7712aa73457a4a821906c6863a"
        },
        {
          "url": "https://git.kernel.org/stable/c/e7187f33c02488697ec0d01d82bf7a3f8deaba8f"
        },
        {
          "url": "https://git.kernel.org/stable/c/48df98d12b15360cd56af5c1f460307b340c1197"
        },
        {
          "url": "https://git.kernel.org/stable/c/ee933694645dac062d65fc2743f92bc06fa0db6b"
        },
        {
          "url": "https://git.kernel.org/stable/c/35d0ed82d03e5ee77ea4f31f20e29562a7721649"
        }
      ],
      "title": "libceph: Fix potential out-of-bounds access in osdmap_decode()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-52958",
    "datePublished": "2026-06-24T16:28:39.723Z",
    "dateReserved": "2026-06-09T07:44:35.373Z",
    "dateUpdated": "2026-08-05T12:32:08.518Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…