Junglewise Threat Intelligence

CVE-2025-68285: Linux Kernel libceph use-after-free in have_mon_and_osd_map

CVE-2025-68285 · Severity: critical · CVSS 9.8 · Published 2025-12-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Ceph network storage client that could lead to a system crash or unauthorized memory access. The issue occurs when the system attempts to connect to a storage cluster and simultaneously receives updates about the cluster's layout, causing a conflict in how memory is managed. An exploit could potentially allow an attacker to disrupt storage services or gain a foothold in the system.

Technical details

A use-after-free vulnerability exists in the libceph module of the Linux kernel due to a race condition in the have_mon_and_osd_map() function. The vulnerability occurs because the wait loop in __ceph_open_session() dereferences monmap and osdmap pointers without holding the necessary mutexes (client->monc.mutex and client->osdc.lock), while concurrent threads may be freeing and replacing these maps. An attacker could potentially trigger this race condition during the mount process to cause a kernel panic or achieve arbitrary code execution. The fix involves rewriting the wait loop to ensure proper locking is maintained during map validation and improving timeout handling.

Affected products

  • Linux Linux Kernel 6.14-rc2 and earlier versions

Timeline

  • 2025-11-03: other: Patch authored
  • 2025-12-07: patched: Patch committed to stable tree
  • 2025-12-16: advisory: CVE published

References

Related threats