Database/Kernel, userspace & hypervisor
Linux libceph: integer overflow in osdmap decoding defeats the bounds check and reads out of bounds
Impact
The bounds check for the new_state section of a CEPH_MSG_OSD_MAP is computed by multiplying a length read out of the incoming message, and that multiplication can overflow, so an oversized len passes validation and decoding then reads past the end of the buffer. The fix switches to check_mul_overflow() and rejects such maps. The exposure is out-of-bounds reads in kernel context on every node running a kernel CephFS or RBD client, which in practice means a crashed node - and on a GPU host that is the loss of whatever job was resident plus a reboot to recover. As with the sibling libceph fixes, the NVD AV:N 9.8 rating assumes an attacker can already put a crafted osdmap in front of the client, which means a compromised or impersonated monitor or an unauthenticated storage network, not an arbitrary remote party.
Who can reach it
Whoever can hand the kernel client an OSD map: a compromised Ceph monitor, or an on-path attacker on a storage network where msgr2 authentication and encryption are not enforced. Not reachable from a tenant workload on the node.
What to do
Move to a stable kernel containing the fix (five backport commits are on the record) and reboot each node with a kernel Ceph mount; a mounted client rules out module reload, so plan drain-and-reboot and batch it with the other libceph fixes published the same day. In the interim, keeping clients on authenticated msgr2 over an isolated storage network is what actually keeps a crafted osdmap away from the decoder.
References
Related entries
- Linux kernel libceph: unbounded pg_temp length lets a malicious monitor cause a stack out-of-bounds writeCVE-2026-68159 · Linux kernel libceph (OSDMap pg_temp / pg_upmap / pg_upmap_items decode)Critical
- CephFS kernel client (ceph.ko, ceph_handle_caps): The kernel trusts snap_trace_len straight off the wire, so aCVE-2026-68160 · CephFS kernel client (ceph.ko, ceph_handle_caps)Critical
- Linux kernel (net/xfrm): When IPsec crypto offload takes a GSO segment asynchronously, the segment is unlinked from theCVE-2026-68426 · Linux kernel (net/xfrm)Critical
- Linux kernel (net/xfrm): The ESP-in-TCP send path mis-tracked scatter-gather message offsets and socket memory chargesCVE-2026-72041 · Linux kernel (net/xfrm)Critical
- Linux kernel LIO target: unbounded iSCSI TransportID parse in PR OUT reads past the parameter bufferCVE-2026-72084 · Linux kernel LIO SCSI target (PERSISTENT RESERVE OUT TransportID parsing, iSCSI FORMAT CODE 01b)Critical
- Linux kernel - NVMe-oF target DH-HMAC-CHAP authentication, drivers/nvme/target/fabrics-cmd-auth.c: The sibling of theCVE-2026-72130 · Linux kernel - NVMe-oF target DH-HMAC-CHAP authentication, drivers/nvme/target/fabrics-cmd-auth.cCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.