Database/Kernel, userspace & hypervisor
CephFS/RBD kernel client (libceph messenger v2): A signedness bug in net/ceph/messenger_v2.c turns an attacker-chosen
Impact
A signedness bug in net/ceph/messenger_v2.c turns an attacker-chosen frame length into a buffer overflow inside the kernel, reachable through HELLO and other early control frames. That is remote code execution in kernel context on every node that mounts CephFS or maps RBD.
Who can reach it
Anything that can complete or spoof the start of a messenger v2 handshake with a client node - a rogue mon/OSD, or an attacker on the storage network able to answer a client's connection.
What to do
Update to Linux 6.4.5 or later (or a vendor kernel with the backport) on all Ceph client nodes and reboot. Restrict which hosts can reach client nodes on the Ceph ports and keep the storage fabric off tenant-routable networks.
References
Related entries
- Linux kernel (drivers/iommu/iommufd): Splitting a mapping area - which is what a partial unmap does - leaves theCVE-2023-52801 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu): The IOVA allocator's retry path overflows, so the lower-bound check is made against zeroCVE-2023-52910 · Linux kernel (drivers/iommu)High
- Linux kernel (drivers/iommu/iommufd): An unmap runs off the end of the pinned page list and drops pin counts on pagesCVE-2023-53630 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The same hardware page table gets linked into an address space's page-table listCVE-2023-54043 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/iommu/iommufd): The pfn batch end index is left at zero after a carry, so the unpin path walks anCVE-2023-54060 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (net/smc): The IB port-up handler walks the global link-group list without holding its lock, so a fabricCVE-2023-54318 · Linux kernel (net/smc)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.