CRITICAL Introduced in 5.3
libceph OsdMap OOB
CVE-2026-52958
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
KernelScan AI8.2HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdmap_decode() When decoding osd_state and osd_weight from an incoming osdmap in osdmap_decode(), both are decoded for each osd, i.e., map->max_osd times. The ceph_decode_need() check only accounts for sizeof(*map->osd_weight) once. This can potentially result in an out-of-bounds memory access if the incoming message is corrupted such that the max_osd value exceeds the actual content of the osdmap message. This patch fixes the issue by changing the corresponding part in the ceph_decode_need() check to account for map->max_osd*sizeof(*map->osd_weight).
02KernelScan AI Analysis
Risk summary
A malicious or compromised Ceph monitor/OSD server can send a crafted osdmap message with a max_osd value that exceeds the actual message content, causing the kernel client to read beyond the allocated buffer. Because the out-of-bounds read length is effectively unbounded (controlled by the attacker-supplied max_osd), this can result in information disclosure of kernel memory (C:L) or a kernel panic/oops due to hitting unmapped pages (A:H). No privileges on the victim system are required if the attacker controls or can spoof the Ceph cluster endpoint.
Vulnerability analysis
The vulnerability is an out-of-bounds read in osdmap_decode() in net/ceph/osdmap.c. When decoding osd_state and osd_weight fields from an incoming osdmap message, both fields are decoded map->max_osd times in a loop. The ceph_decode_need() bounds check prior to this loop incorrectly accounts for only sizeof(*map->osd_weight) (a single entry) rather than map->max_osd * sizeof(*map->osd_weight) (all entries). If a crafted or corrupted osdmap message contains a max_osd value larger than the actual data present, the bounds check passes but subsequent per-OSD decoding reads beyond the end of the message buffer. The fix multiplies the size by map->max_osd to correctly validate that sufficient bytes exist for all OSD weight entries. The attack surface is network-reachable: any kernel configured as a Ceph client that connects to a malicious or MITM'd Ceph monitor could be exploited without any local privileges. The CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H, yielding a base score of 8.2 (High). Confidentiality is Low because the primitive is a constrained out-of-bounds read; Availability is High because a large max_osd value causes the decoder to traverse unmapped pages, resulting in a kernel panic.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.1 | 5.3 | 6.1.175 | 8713bbc4b2b9 |
| 6.12 | 5.3 | 6.12.91 | e7187f33c024 |
| 6.18 | 5.3 | 6.18.33 | 48df98d12b15 |
| 7.0 | 5.3 | 7.0.10 | ee933694645d |
| 6.6 | 5.3 | 6.6.141 | 0d2dd7e6bb74 |
| mainline | 5.3 | 7.1 | 35d0ed82d03e |
| 5.10 | 5.3 | 5.10.258 | 36a79759a288 |
| 5.15 | 5.3 | 5.15.209 | 3f2575bb7f95 |