Junglewise Threat Intelligence

CVE-2026-68082: Linux kernel libceph out-of-bounds read in decode_lockers

CVE-2026-68082 · Severity: critical · CVSS 9.8 · Published 2026-08-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Ceph client library contains two unsafe buffer read operations that allow a malicious or compromised Ceph Object Storage Daemon (OSD) to read memory past buffer boundaries. An attacker with control of an OSD can trigger these reads during RBD exclusive lock acquisition, potentially exposing sensitive kernel memory to an untrusted storage server in shared Ceph deployments.

Technical details

The decode_lockers() function in cls_lock_client.c contains two unsafe bare decode operations that lack bounds checking. First, ceph_decode_32(p) reads the num_lockers field without verifying the buffer has sufficient data, allowing an OSD to send struct_len=0 to advance the pointer past the validated boundary. Second, ceph_decode_8(p) after the decode loop can read one byte past the buffer if num_lockers is crafted to advance p exactly to the buffer end. Both operations read garbage values that are used directly in subsequent logic (kzalloc_objs and lock type discrimination). The fix replaces bare decode operations with safe variants (ceph_decode_32_safe and ceph_decode_8_safe) that perform proper bounds checking before reading. Attack requires the kernel client to issue lock.get_info class method, which is typical during RBD exclusive lock acquisition.

Affected products

  • Linux Linux kernel <unknown>

Timeline

  • 2026-08-08: disclosed

Related threats