KernelScan.io

CRITICAL Introduced in 2.6.34

libceph CrushDecode OOB

CVE-2026-52955

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI8.6HIGH

01

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crush_decode() A message of type CEPH_MSG_OSD_MAP containing a crush map with at least one bucket has two fields holding the bucket algorithm. If the values in these two fields differ, an out-of-bounds access can occur. This is the case because the first algorithm field (alg) is used to allocate the correct amount of memory for a bucket of this type, while the second algorithm field inside the bucket (b->alg) is used in the subsequent processing. This patch fixes the issue by adding a check that compares alg and b->alg and aborts the processing in case they differ. Furthermore, b->alg is set to 0 in this case, because the destruction of the crush map also uses this field to determine the bucket type, which can again result in an out-of-bounds access when trying to free the memory pointed to by the fields of the bucket. To correctly free the memory allocated for the bucket in such a case, the corresponding call to kfree is moved from the algorithm-specific crush_destroy_bucket functions to the generic crush_destroy_bucket().

02

Engine v0.3.0

Risk summary

A malicious or compromised Ceph OSD server can send a crafted CEPH_MSG_OSD_MAP message containing a CRUSH map with mismatched bucket algorithm fields, triggering an out-of-bounds memory access in the kernel client. This can leak kernel heap data (confidentiality impact), corrupt memory via invalid kfree operations (integrity impact), and cause a kernel panic (availability impact). Any Linux system running the Ceph client and connected to an untrusted or compromised Ceph cluster is at risk.

Affectednet/ceph/osdmap.c, net/ceph/crush/crush.c (libceph CRUSH map decoder)

Vulnerability analysis

The vulnerability exists in crush_decode() in net/ceph/osdmap.c. When decoding a CRUSH map bucket, the code first reads an 'alg' field to determine the bucket type and allocates memory accordingly (e.g., struct crush_bucket_uniform vs crush_bucket_straw2). It then reads a second 'b->alg' field from inside the bucket data. If these two values differ, subsequent processing and destruction use b->alg to dispatch to algorithm-specific code paths that assume a different struct layout than what was allocated, resulting in out-of-bounds reads and writes. During cleanup, the wrong destroy function reads pointer fields from beyond the allocated struct and passes them to kfree, causing invalid free operations and heap corruption. The fix adds a consistency check comparing alg and b->alg, aborting with an error if they differ (setting b->alg=0 to prevent OOB access during cleanup), and moves the kfree(b) call from algorithm-specific destroy functions to the generic crush_destroy_bucket() to ensure correct cleanup in all cases. The attack surface is network-reachable: a Ceph client receives OSD map messages from the monitor/OSD servers over the network, so a malicious or compromised server can trigger this without any local access.

03

BranchIntroducedFixed inPatch commit
5.102.6.345.10.2586e70ef53e818
6.12.6.346.1.1753f42508191e1
6.122.6.346.12.91cceb10023e76
6.182.6.346.18.330f3604cbe4df
7.02.6.347.0.10fb176a99e4c1
mainline2.6.347.14c79fc2d5986
6.62.6.346.6.141ea0d42137f0c
5.152.6.345.15.209ebe76d58a48a