Executive brief
A vulnerability in the Linux kernel's Ceph storage client could allow a remote attacker to crash the system. The issue occurs when the system processes specially crafted network packets containing invalid storage device indexes. This can lead to a kernel panic, resulting in a complete denial of service for the affected machine.
Technical details
A vulnerability in net/ceph/osdmap.c within the Linux kernel's libceph module stems from the use of BUG_ON() macros instead of proper error handling when validating OSD (Object Storage Daemon) indexes. These indexes are parsed from untrusted network packets in functions such as decode_new_primary_affinity and decode_new_up_state_weight. A remote attacker can provide an OSD index that exceeds the map->max_osd boundary, triggering the BUG_ON() macro and causing a kernel panic (DoS). The fix replaces these macros with explicit bounds checks that return an error (e_inval) instead of crashing the system. Patches are available in various stable kernel branches including 6.1.159, 6.6.119, 6.12.61, and 6.17.11.
Affected products
- Linux Linux Kernel 2.6.34 to 6.1.158, 6.6.118, 6.12.60, 6.17.10
Timeline
- 2025-11-17: other: Patch authored
- 2025-12-16: advisory: CVE published
- 2025-12-07: patched: Fix committed to stable trees
References
- https://git.kernel.org/stable/c/57f5fbae9f1024aba17ff75e00433324115c548a
- https://git.kernel.org/stable/c/b4368b7f97014e1015445d61abd0b27c4c6e8424
- https://git.kernel.org/stable/c/becc488a4d864db338ebd4e313aa3c77da24b604
- https://git.kernel.org/stable/c/e67e3be690f5f7e3b031cf29e8d91e6d02a8e30d
- https://git.kernel.org/stable/c/ec3797f043756a94ea2d0f106022e14ac4946c02