Executive brief
A vulnerability was identified in the Linux kernel's Ceph network storage client. A maliciously crafted or corrupted network message could cause the system to read data outside of its intended memory boundaries. This could lead to system instability or a potential crash, affecting the reliability of servers using Ceph storage.
Technical details
An out-of-bounds read vulnerability exists in the Linux kernel's libceph module within the osdmap_decode() function in net/ceph/osdmap.c. The root cause is an incorrect length check in ceph_decode_need() which only accounted for a single OSD weight entry instead of the full array defined by max_osd. A remote attacker or a compromised Ceph OSD could send a specially crafted osdmap message where the max_osd value exceeds the actual message buffer size, leading to an out-of-bounds access during decoding. This issue has been patched in multiple stable kernel branches including 5.10.y, 5.15.y, 6.1.y, 6.6.y, 6.8.y, and 6.9.y.
Affected products
- Linux Linux Kernel 5.3 to 5.10.258, 5.15.160, 6.1.92, 6.6.32, 6.8.11, 6.9.2
Timeline
- 2026-05-05: other: Vulnerability fixed in source code
- 2026-06-24: advisory: CVE-2026-52958 published by NVD
References
- https://git.kernel.org/stable/c/0d2dd7e6bb74fd7712aa73457a4a821906c6863a
- https://git.kernel.org/stable/c/35d0ed82d03e5ee77ea4f31f20e29562a7721649
- https://git.kernel.org/stable/c/36a79759a288961b1ff28a68ec2d1f56f6848098
- https://git.kernel.org/stable/c/3f2575bb7f955d42569d96c3e04fa958a0dcf4b4
- https://git.kernel.org/stable/c/48df98d12b15360cd56af5c1f460307b340c1197
- https://git.kernel.org/stable/c/8713bbc4b2b9ad78f803978e54b7e49dd21bd9be
- https://git.kernel.org/stable/c/e7187f33c02488697ec0d01d82bf7a3f8deaba8f