Junglewise Threat Intelligence

CVE-2025-68284: Linux Kernel libceph out-of-bounds write in handle_auth_session_key

CVE-2025-68284 · Severity: critical · CVSS 9.8 · Published 2025-12-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Ceph storage client that could allow an attacker to perform unauthorized memory writes. This component is responsible for communicating with Ceph storage clusters, which are often used for large-scale data storage in enterprise environments. An exploit could lead to a complete system compromise, potentially resulting in data theft, service outages, or unauthorized access to sensitive information.

Technical details

An out-of-bounds write vulnerability exists in the handle_auth_session_key() function within net/ceph/auth_x.c of the Linux kernel. The issue stems from insufficient boundary validation of the 'len' field, which is parsed directly from untrusted network packets. When decrypting connection secrets or processing service tickets, the kernel failed to verify that the provided length did not exceed the actual buffer size. An attacker can exploit this by sending a malicious Ceph authentication response to trigger a memory corruption. The fix introduces ceph_decode_need() checks to ensure the packet length matches the expected buffer boundaries. Patches are available in various stable kernel branches including 5.15.197, 6.1.159, 6.6.119, 6.12.61, and 6.17.11.

Affected products

  • Linux Linux Kernel 5.11 to 6.17.11

Timeline

  • 2025-11-14: other: Vulnerability reported by researcher
  • 2025-11-27: patched: Initial fix committed to mainline kernel
  • 2025-12-16: advisory: CVE-2025-68284 published

References

Related threats