Junglewise Threat Intelligence

CVE-2026-52954: Linux Kernel libceph Denial of Service in decode_choose_args

CVE-2026-52954 · Severity: info · CVSS 5.5 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Ceph network storage client could allow a remote attacker to crash the system. By sending a specially crafted or corrupted storage map message, an attacker can trigger a kernel panic (BUG), leading to a denial-of-service condition. This affects systems using the libceph module to connect to Ceph storage clusters.

Technical details

A vulnerability exists in the libceph implementation within the Linux kernel's net/ceph/osdmap.c. The function decode_choose_args() processes CEPH_MSG_OSD_MAP messages containing CRUSH maps. When decoding crush_choose_arg_maps, the code uses an asserting rbtree insertion function (insert_choose_arg_map). If a message contains two maps with the same choose_args_index, the assertion fails, triggering a kernel BUG and immediate system halt. The fix replaces the asserting insertion with a non-asserting check (__insert_choose_arg_map) that returns an error and rejects the malformed message instead of crashing. This can be triggered by a malicious or corrupted OSD map sent over the network.

Affected products

  • Linux Linux Kernel 5.10.258, 5.15.160, 6.1.92, 6.6.32, 6.8.11, 6.9.2

Timeline

  • 2026-05-12: other: Vulnerability fixed in source code by Raphael Zimmer
  • 2026-05-23: patched: Patches committed to various stable kernel branches
  • 2026-06-24: disclosed: CVE-2026-52954 published

References

Related threats