Junglewise Threat Intelligence

CVE-2025-68283: Linux Kernel libceph denial of service via OSD index validation

CVE-2025-68283 · Severity: high · CVSS 7.5 · Published 2025-12-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Ceph storage client could allow a remote attacker to crash the system. The issue occurs when the system processes specially crafted network packets containing invalid storage device indexes. This can lead to a kernel panic, resulting in a complete denial of service for the affected machine.

Technical details

A vulnerability in net/ceph/osdmap.c within the Linux kernel's libceph module stems from the use of BUG_ON() macros instead of proper error handling when validating OSD (Object Storage Daemon) indexes. These indexes are parsed from untrusted network packets in functions such as decode_new_primary_affinity and decode_new_up_state_weight. A remote attacker can provide an OSD index that exceeds the map->max_osd boundary, triggering the BUG_ON() macro and causing a kernel panic (DoS). The fix replaces these macros with explicit bounds checks that return an error (e_inval) instead of crashing the system. Patches are available in various stable kernel branches including 6.1.159, 6.6.119, 6.12.61, and 6.17.11.

Affected products

  • Linux Linux Kernel 2.6.34 to 6.1.158, 6.6.118, 6.12.60, 6.17.10

Timeline

  • 2025-11-17: other: Patch authored
  • 2025-12-16: advisory: CVE published
  • 2025-12-07: patched: Fix committed to stable trees

References

Related threats