HIGH Introduced in 4.13
libceph CRUSH ChooseArgs Deref
CVE-2026-52957
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
KernelScan AI7.5HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential null-ptr-deref in decode_choose_args() A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself contains a CRUSH map. When decoding this CRUSH map in crush_decode(), an array of max_buckets CRUSH buckets is decoded, where some indices may not refer to actual buckets and are therefore set to NULL. The received CRUSH map may optionally contain choose_args that get decoded in decode_choose_args(). When decoding a crush_choose_arg_map, a series of choose_args for different buckets is decoded, with the bucket_index being read from the incoming message. It is only checked that the bucket index does not exceed max_buckets, but not that it doesn't point to an index with a NULL bucket. If a (potentially corrupted) message contains a crush_choose_arg_map including such a bucket_index, a null pointer dereference may occur in the subsequent processing when attempting to access the bucket with the given index. This patch fixes the issue by extending the affected check. Now, it is only attempted to access the bucket if it is not NULL.
02KernelScan AI Analysis
Risk summary
A Ceph client connected to a malicious or compromised OSD monitor can receive a crafted CEPH_MSG_OSD_MAP message containing a CRUSH map with a choose_args entry referencing a NULL bucket index. Processing this message triggers a NULL pointer dereference in the kernel, causing a system crash. Any system running a Ceph client (e.g., mounting CephFS or using RBD) is at risk if it connects to an untrusted or compromised Ceph cluster.
Vulnerability analysis
The vulnerability is a NULL pointer dereference in decode_choose_args() in net/ceph/osdmap.c. When decoding a CRUSH map received via a CEPH_MSG_OSD_MAP network message, the kernel allocates an array of up to max_buckets bucket pointers, some of which may legitimately be NULL (sparse array). When subsequently decoding choose_args, a bucket_index is read from the network message and checked only to be less than max_buckets, but not that c->buckets[bucket_index] is non-NULL. If the message (from a malicious or corrupted server) supplies a bucket_index pointing to a NULL slot, the subsequent dereference of c->buckets[bucket_index]->size causes a kernel NULL pointer dereference and system crash. The fix adds a NULL check: the condition now also triggers an error if c->buckets[bucket_index] is NULL, preventing the dereference. The attack requires a network connection to a Ceph cluster (the attacker must control or compromise the OSD monitor, or be able to inject/corrupt the OSD map message in transit); no privileges on the victim system are required.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 4.13 | 5.10.258 | d55ffad8d422 |
| 5.15 | 4.13 | 5.15.209 | 301286c0ccd3 |
| 6.1 | 4.13 | 6.1.175 | 7169f326a23d |
| 6.12 | 4.13 | 6.12.91 | 312ec973efac |
| 7.0 | 4.13 | 7.0.10 | a20e16ebfe2f |
| mainline | 4.13 | 7.1 | 28b0a2ab8c82 |
| 6.6 | 4.13 | 6.6.141 | d7a65a34d245 |
| 6.18 | 4.13 | 6.18.33 | f2f95e6d4b97 |