Database/Kernel, userspace & hypervisor
Linux kernel libceph: truncated monitor reply decodes stale bytes from the reused buffer
Impact
handle_get_version_reply() bounded its decode by front_alloc_len - the size of the reused reply buffer - instead of front.iov_len, the bytes actually received. A truncated MON_GET_VERSION_REPLY therefore passes the length check and the second u64 is read from leftover bytes of an earlier message, an uninitialized kernel memory read whose value then feeds Ceph client logic. This only matters on nodes that mount CephFS or map RBD through the in-kernel client; GPU nodes that reach Ceph through librbd, ceph-fuse or an S3 gateway do not load this code. NVD scores it 8.6 with high availability impact, which is consistent with a client-side hang or crash on a node whose storage mount cannot be dropped without evicting the jobs using it.
Who can reach it
Whoever can answer as the Ceph monitor to the kernel client: a compromised MON, or an on-path attacker on the storage network where messenger v2 secure mode is not enforced. No credentials beyond what the mount already presents; no local access to the GPU node is required.
What to do
Take the stable-kernel update containing the fix (five stable commits are linked). This is a kernel change, so the rollout is drain the node and reboot it onto the patched kernel - or a live-patch stream if your vendor ships one. Where the reboot cannot be scheduled soon, reduce exposure by enforcing msgr2 secure mode between clients and monitors so an off-path attacker cannot forge truncated replies.
References
Related entries
- sudo: intercept policy checks skipped for execveat, letting allowed users run denied commandsCVE-2026-82474 · sudo (ptrace-based intercept mode, execveat/fexecve path)High
- Linux kernel (arch/x86/kvm/svm): Hardware ignores the low five bits of CR3 when loading PDPTEs, but KVM's nested SVMCVE-2024-50115 · Linux kernel (arch/x86/kvm/svm)High
- Linux kernel arm_ffa: unvalidated notification layout drives out-of-bounds read of the shared RX bufferCVE-2026-64081 · Linux kernel arm_ffa (Arm FF-A framework notification parsing)High
- Linux kernel (arch/x86/kvm): A nested guest can put an out-of-range virtual-processor ID into an enlightened VMCS andCVE-2026-64247 · Linux kernel (arch/x86/kvm)High
- Linux kernel virtio-net: loose length check in receive_big() lets a malicious backend write past the frag arrayCVE-2026-64552 · Linux kernel virtio-net (receive_big() length validation)High
- Linux kernel io_uring: per-task restrictions are freed across exec, so post-exec rings are unrestrictedCVE-2026-80713 · Linux kernel io_uring (per-task restrictions dropped on exec)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.