Executive brief
A vulnerability in the Linux kernel's Ceph network storage client could allow a remote attacker to crash the system. By sending a specially crafted or corrupted storage map message, an attacker can trigger a kernel panic (BUG), leading to a denial-of-service condition. This affects systems using the libceph module to connect to Ceph storage clusters.
Technical details
A vulnerability exists in the libceph implementation within the Linux kernel's net/ceph/osdmap.c. The function decode_choose_args() processes CEPH_MSG_OSD_MAP messages containing CRUSH maps. When decoding crush_choose_arg_maps, the code uses an asserting rbtree insertion function (insert_choose_arg_map). If a message contains two maps with the same choose_args_index, the assertion fails, triggering a kernel BUG and immediate system halt. The fix replaces the asserting insertion with a non-asserting check (__insert_choose_arg_map) that returns an error and rejects the malformed message instead of crashing. This can be triggered by a malicious or corrupted OSD map sent over the network.
Affected products
- Linux Linux Kernel 5.10.258, 5.15.160, 6.1.92, 6.6.32, 6.8.11, 6.9.2
Timeline
- 2026-05-12: other: Vulnerability fixed in source code by Raphael Zimmer
- 2026-05-23: patched: Patches committed to various stable kernel branches
- 2026-06-24: disclosed: CVE-2026-52954 published
References
- https://git.kernel.org/stable/c/0a1265a9ab875f92b6a3ffb497404f46cf9d76a3
- https://git.kernel.org/stable/c/0b6a3bcb91bc5bfeda39f0df3b71bab62c13e9da
- https://git.kernel.org/stable/c/4d2b37abda9536808655830d683dc491d31741a8
- https://git.kernel.org/stable/c/534ebc08df97c47d4c7596f336fa31ecbf91519c
- https://git.kernel.org/stable/c/80c73bd1b2b04355d1d0c29be8ccbd25a380905d
- https://git.kernel.org/stable/c/c7bf7864e2924fa5508ac270b0e9364bc13d5a6c
- https://git.kernel.org/stable/c/d289478cfc0bcf81c7914200d6abdcb78bd04ded