Junglewise Threat Intelligence

CVE-2026-43407: Linux Kernel libceph out-of-bounds access in ceph_handle_auth_reply

CVE-2026-43407 · Severity: critical · CVSS 9.1 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's Ceph network storage client. An attacker could send a specially crafted authentication reply message to trigger a system crash or potentially access sensitive memory. This affects systems using Ceph for distributed storage, potentially impacting data availability and system stability.

Technical details

An integer overflow vulnerability exists in the ceph_handle_auth_reply() function within the libceph module of the Linux kernel. When processing a CEPH_MSG_AUTH_REPLY message, the payload_len and result_msg_len fields are stored as signed integers. A malicious message with a length value greater than INT_MAX causes an overflow, resulting in a negative value that bypasses ceph_decode_need() checks and leads to out-of-bounds memory access. This can result in a kernel panic (DoS) or information disclosure. The issue has been patched by changing the length variables to unsigned 32-bit integers (u32) and adding explicit sanity checks against the segment length.

Affected products

  • Linux Linux Kernel 2.6.34.1 to 5.10.253, 5.11 to 5.15.203, 5.16 to 6.1.167, 6.2 to 6.6.130, 6.7 to 6.12.78, 6.13 to 6.18.19, 6.19 to 6.19.9

Timeline

  • 2026-03-10: other: Patch authored
  • 2026-03-25: patched: Patch committed to stable tree
  • 2026-05-08: advisory: CVE published

References

Related threats