KernelScan.io

HIGH Introduced in 4.13

libceph CRUSH ChooseArgs Panic

CVE-2026-52954

CVSS 7.5 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: libceph: handle rbtree insertion error in decode_choose_args() A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself contains a CRUSH map. The received CRUSH map may optionally contain choose_args that get decoded in decode_choose_args(). In this function, num_choose_arg_maps is read from the message, and a corresponding number of crush_choose_arg_maps gets decoded afterwards. Each crush_choose_arg_map has a choose_args_index, which serves as the key when inserting it into the choose_args rbtree of the decoded crush_map. If a (potentially corrupted) message contains two crush_choose_arg_maps with the same index, the assertion in insert_choose_arg_map() triggers a kernel BUG when trying to insert the second crush_choose_arg_map. This patch fixes the issue by switching to the non-asserting rbtree insertion function and rejecting the message if the insertion fails. [ idryomov: changelog ]

02

Engine v0.3.0

Risk summary

A Ceph client connected to a malicious or compromised OSD server can receive a crafted OSD map message containing a CRUSH map with duplicate choose_args indices. Processing this message triggers a kernel BUG assertion in insert_choose_arg_map(), causing a kernel panic and denial of service. Any system running a Ceph client (e.g., mounting a CephFS volume or using RBD) is at risk if it can be directed to connect to a malicious Ceph monitor/OSD.

Affectednet/ceph/osdmap.c (libceph OSD map decoder)

Vulnerability analysis

The vulnerability is a reachable assertion (kernel BUG) in the libceph OSD map decoder. When decoding a CRUSH map's choose_args section, decode_choose_args() reads num_choose_arg_maps from the network message and iterates, inserting each crush_choose_arg_map into an rbtree keyed by choose_args_index. The original insert_choose_arg_map() function uses BUG_ON() to assert that no duplicate key exists. If a crafted or corrupted CEPH_MSG_OSD_MAP message contains two crush_choose_arg_maps with the same index, the second insertion hits the BUG_ON(), triggering a kernel panic. The fix replaces the asserting insert with __insert_choose_arg_map(), which returns false on duplicate rather than panicking, and the decoder then returns -EEXIST to reject the malformed message. The attack surface is network-reachable: any Ceph client that processes OSD map messages from a server it is connected to can be triggered. A malicious or MITM'd Ceph server can send the crafted message to any connected client without requiring privileges on the client system.

03

BranchIntroducedFixed inPatch commit
6.14.136.1.1750b6a3bcb91bc
6.184.136.18.334d2b37abda95
6.64.136.6.141534ebc08df97
mainline4.137.1d289478cfc0b
7.04.137.0.100a1265a9ab87
6.124.136.12.9180c73bd1b2b0
5.104.135.10.258c7bf7864e292
5.154.135.15.209f47430fc1f81