Junglewise Threat Intelligence

CVE-2026-52958: Linux Kernel libceph out-of-bounds access in osdmap_decode

CVE-2026-52958 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Ceph network storage client. A maliciously crafted or corrupted network message could cause the system to read data outside of its intended memory boundaries. This could lead to system instability or a potential crash, affecting the reliability of servers using Ceph storage.

Technical details

An out-of-bounds read vulnerability exists in the Linux kernel's libceph module within the osdmap_decode() function in net/ceph/osdmap.c. The root cause is an incorrect length check in ceph_decode_need() which only accounted for a single OSD weight entry instead of the full array defined by max_osd. A remote attacker or a compromised Ceph OSD could send a specially crafted osdmap message where the max_osd value exceeds the actual message buffer size, leading to an out-of-bounds access during decoding. This issue has been patched in multiple stable kernel branches including 5.10.y, 5.15.y, 6.1.y, 6.6.y, 6.8.y, and 6.9.y.

Affected products

  • Linux Linux Kernel 5.3 to 5.10.258, 5.15.160, 6.1.92, 6.6.32, 6.8.11, 6.9.2

Timeline

  • 2026-05-05: other: Vulnerability fixed in source code
  • 2026-06-24: advisory: CVE-2026-52958 published by NVD

References

Related threats