Database/Kernel, userspace & hypervisor
Linux kernel libceph: NULL dereference in CRUSH locality lookup when a parent bucket's type name is missing
Impact
During localized read selection the client walks a parent bucket whose name is present in the CRUSH map but whose type has no entry in type_names; get_immediate_parent() then dereferences a NULL type_cn and hands an invalid pointer to strcmp(), producing a NULL pointer dereference in the kernel. A malformed CRUSH hierarchy - corrupted in transit or served by a compromised monitor - therefore crashes any node using the in-kernel CephFS or RBD client with localized reads enabled. On a GPU node that is a hard stop for every job resident on it, and the node has to be rebooted rather than drained gracefully. The fix skips malformed parent buckets and falls back to treating the read as non-local, so correctness degrades rather than the machine dying.
Who can reach it
Whoever controls the CRUSH map content the kernel client receives - realistically a compromised or impersonated Ceph monitor, or injection on an unauthenticated storage network. Requires the client to be doing localized read selection.
What to do
Pick up the stable-kernel fix that guards the missing CRUSH type name lookup (backported across five stable branches, see the git.kernel.org commits) and reboot each node running the kernel Ceph client. Kernel change, so drain and reboot per node; there is no runtime mitigation short of not using the in-kernel client or disabling localized reads.
References
Related entries
- Linux kernel (net/tls): A remote peer sends a zero-length TLS 1.3 application_data record - which the RFC explicitlyCVE-2026-72330 · Linux kernel (net/tls)High
- OpenSSL: SSL_set_SSL_CTX mid-handshake leaves a stale slot count, allowing heap OOB read/writeCVE-2026-72897 · OpenSSL TLS server (SSL_set_SSL_CTX certificate-slot array)High
- Linux kernel (drivers/nvme/target): A client that completes the TLS handshake against the NVMe-oF TCP target and thenCVE-2026-74385 · Linux kernel (drivers/nvme/target)High
- Linux kernel (drivers/nvme/target): Every connection that dies partway through queue allocation on the NVMe-oF TCPCVE-2026-74386 · Linux kernel (drivers/nvme/target)High
- Linux kernel libiscsi: out-of-bounds read leaks stale connection data into the SCSI sense bufferCVE-2026-74557 · Linux kernel libiscsi (SCSI Response sense-data bounds check)High
- Linux kernel LIO iblock: missing PR handler checks let PERSISTENT RESERVE OUT NULL-deref the kernelCVE-2026-80691 · Linux kernel SCSI target (LIO) iblock backend, PERSISTENT RESERVE OUT handlingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.