Junglewise Threat Intelligence

CVE-2025-39880: Linux Kernel libceph type confusion in messenger.c

CVE-2025-39880 · Severity: critical · CVSS 9.8 · Published 2025-09-23

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Ceph network messenger component, which handles communication for Ceph distributed storage. Due to a coding error, the system may incorrectly access memory when using newer versions of the communication protocol, potentially leading to data corruption or system instability. This could impact the reliability and security of storage operations in environments using Ceph.

Technical details

A vulnerability exists in the libceph module of the Linux kernel due to invalid accesses to the ceph_connection_v1_info union member. In messenger.c, the code reads from and writes to the 'v1' union member without verifying if the msgr1 protocol is actually in use. On 64-bit systems, these v1 fields overlap with v2 fields (specifically v1.auth_retry overlaps with v2.out_iter, and v1.connect_seq overlaps with v2.conn_bufs). When the msgr2 protocol is active, these incorrect accesses can lead to bogus value reads or memory corruption via invalid writes. This can result in unauthorized authorizer invalidation or more severe consequences depending on the state of the connection buffers. Patches have been released for various stable kernel branches including 5.15.y, 6.1.y, 6.6.y, and 6.12.y.

Affected products

  • Linux Linux Kernel 5.11 to 5.15.194, 6.1.153, 6.6.107, 6.12.48, 6.16.8

Timeline

  • 2025-07-03: patched: Initial fix authored by Ilya Dryomov
  • 2025-09-23: disclosed: CVE published

References

Related threats