KernelScan.io

HIGH Introduced in 2.6.12

libceph AuthDecrypt OOB

CVE-2026-52956

CVSS 7.5 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

KernelScan AI8.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() In __ceph_x_decrypt(), a part of the buffer p is interpreted as a ceph_x_encrypt_header, and the magic field of this struct is accessed. This happens without any guarantee that the buffer is large enough to hold this struct. The function parameter ciphertext_len represents the length of the ciphertext to decrypt and is guaranteed to be at most the remaining size of the allocated buffer p. However, this value is not necessarily greater than sizeof(ceph_x_encrypt_header). E.g., a message frame of type FRAME_TAG_AUTH_REPLY_MORE, that is just as long to hold the ciphertext at its end with a ciphertext_len of 8 or less, can trigger an out-of-bounds memory access when accessing hdr->magic. This patch fixes the issue by adding a check to ensure that the decrypted plaintext in the buffer is large enough to represent at least the ceph_x_encrypt_header.

02

Engine v0.3.0

Risk summary

A remote, malicious Ceph server or man-in-the-middle attacker can send a crafted FRAME_TAG_AUTH_REPLY_MORE message with a very short ciphertext (≤8 bytes), causing the kernel client to read beyond the decrypted buffer bounds when accessing hdr->magic. This leaks up to 8 bytes of adjacent kernel memory (C:Low) and can potentially trigger a kernel panic (A:High). Systems running the Ceph client (CephFS, RBD, or RADOS) are affected.

Affectednet/ceph/auth_x.c (libceph CephX authentication)

Vulnerability analysis

In __ceph_x_decrypt() in net/ceph/auth_x.c, after decrypting ciphertext into buffer p, the code casts p + ceph_crypt_data_offset(key) to ceph_x_encrypt_header* and reads hdr->magic without first verifying that plaintext_len is at least sizeof(*hdr). A malicious or compromised Ceph server can send an AUTH_REPLY_MORE frame with a ciphertext_len of 8 or fewer bytes. Because the buffer may be sized exactly to the message length, this results in an out-of-bounds read of the 8-byte magic field. The fix adds a bounds check (plaintext_len < sizeof(*hdr)) that returns -EINVAL. The attack is network-reachable and requires no privileges on the client system.

03

BranchIntroducedFixed inPatch commit
7.02.6.127.0.10821365487aa5
mainline2.6.127.1—
4.94.9.64.10c7e9b53aebe4