Junglewise Threat Intelligence

CVE-2026-52956: Linux Kernel libceph out-of-bounds access in __ceph_x_decrypt

CVE-2026-52956 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Ceph storage client that could allow for an out-of-bounds memory access. Ceph is a distributed storage system used to manage large amounts of data across multiple servers. If exploited, this flaw could potentially lead to system instability or crashes when the system processes specifically crafted authentication messages.

Technical details

An out-of-bounds read vulnerability exists in the Linux kernel's libceph module within the net/ceph/auth_x.c component. The function __ceph_x_decrypt() attempts to access the 'magic' field of a ceph_x_encrypt_header struct within a buffer without first verifying that the buffer is large enough to contain the header. Specifically, a message frame of type FRAME_TAG_AUTH_REPLY_MORE with a ciphertext_len of 8 bytes or less can trigger this access. An attacker capable of sending malformed Ceph authentication responses could trigger this flaw, potentially leading to a kernel oops or information disclosure. The issue has been resolved by adding a check to ensure the decrypted plaintext length is at least the size of the expected header.

Affected products

  • Linux Linux Kernel versions before 7.0.10

Timeline

  • 2026-04-28: other: Vulnerability reported by Raphael Zimmer
  • 2026-05-11: patched: Fix committed to mainline kernel
  • 2026-06-24: disclosed: CVE published

References

Related threats