Junglewise Threat Intelligence

CVE-2026-52955: Linux Kernel libceph out-of-bounds access in crush_decode

CVE-2026-52955 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Ceph network storage client. The flaw occurs when processing storage map messages (OSD maps) that contain inconsistent data about how data is distributed across the cluster. An attacker or a compromised storage server could send a specially crafted message that causes the system to access memory incorrectly, potentially leading to a system crash or instability.

Technical details

A vulnerability exists in the libceph implementation within the Linux kernel's net/ceph/osdmap.c. When decoding a CEPH_MSG_OSD_MAP message, the crush_decode() function processes buckets that contain two separate fields for the bucket algorithm. The first field is used to determine the memory allocation size, while the second field (b->alg) is used for subsequent processing. If these fields differ, an out-of-bounds access occurs. Additionally, the crush_destroy_bucket function could trigger a similar out-of-bounds access during error cleanup. The fix implements a consistency check between the two algorithm fields and centralizes memory deallocation to prevent invalid free operations.

Affected products

  • Linux Linux Kernel All versions before 6.9.2, 6.6.32, 6.1.92, 5.15.160, 5.10.218, 5.4.277, 4.19.315, 4.14.346

Timeline

  • 2026-04-22: other: Patch submitted by author
  • 2026-05-11: patched: Patch committed to mainline kernel
  • 2026-06-24: advisory: CVE published

References

Related threats