HIGH Introduced in 4.13
libceph CRUSH ChooseArgs Panic
CVE-2026-52954
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
KernelScan AI7.5HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: libceph: handle rbtree insertion error in decode_choose_args() A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself contains a CRUSH map. The received CRUSH map may optionally contain choose_args that get decoded in decode_choose_args(). In this function, num_choose_arg_maps is read from the message, and a corresponding number of crush_choose_arg_maps gets decoded afterwards. Each crush_choose_arg_map has a choose_args_index, which serves as the key when inserting it into the choose_args rbtree of the decoded crush_map. If a (potentially corrupted) message contains two crush_choose_arg_maps with the same index, the assertion in insert_choose_arg_map() triggers a kernel BUG when trying to insert the second crush_choose_arg_map. This patch fixes the issue by switching to the non-asserting rbtree insertion function and rejecting the message if the insertion fails. [ idryomov: changelog ]
02KernelScan AI Analysis
Risk summary
A Ceph client connected to a malicious or compromised OSD server can receive a crafted OSD map message containing a CRUSH map with duplicate choose_args indices. Processing this message triggers a kernel BUG assertion in insert_choose_arg_map(), causing a kernel panic and denial of service. Any system running a Ceph client (e.g., mounting a CephFS volume or using RBD) is at risk if it can be directed to connect to a malicious Ceph monitor/OSD.
Vulnerability analysis
The vulnerability is a reachable assertion (kernel BUG) in the libceph OSD map decoder. When decoding a CRUSH map's choose_args section, decode_choose_args() reads num_choose_arg_maps from the network message and iterates, inserting each crush_choose_arg_map into an rbtree keyed by choose_args_index. The original insert_choose_arg_map() function uses BUG_ON() to assert that no duplicate key exists. If a crafted or corrupted CEPH_MSG_OSD_MAP message contains two crush_choose_arg_maps with the same index, the second insertion hits the BUG_ON(), triggering a kernel panic. The fix replaces the asserting insert with __insert_choose_arg_map(), which returns false on duplicate rather than panicking, and the decoder then returns -EEXIST to reject the malformed message. The attack surface is network-reachable: any Ceph client that processes OSD map messages from a server it is connected to can be triggered. A malicious or MITM'd Ceph server can send the crafted message to any connected client without requiring privileges on the client system.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.1 | 4.13 | 6.1.175 | 0b6a3bcb91bc |
| 6.18 | 4.13 | 6.18.33 | 4d2b37abda95 |
| 6.6 | 4.13 | 6.6.141 | 534ebc08df97 |
| mainline | 4.13 | 7.1 | d289478cfc0b |
| 7.0 | 4.13 | 7.0.10 | 0a1265a9ab87 |
| 6.12 | 4.13 | 6.12.91 | 80c73bd1b2b0 |
| 5.10 | 4.13 | 5.10.258 | c7bf7864e292 |
| 5.15 | 4.13 | 5.15.209 | f47430fc1f81 |