KernelScan.io

CRITICAL Introduced in 5.3

libceph OsdMap OOB

CVE-2026-52958

CVSS 9.1 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

KernelScan AI8.2HIGH

01

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdmap_decode() When decoding osd_state and osd_weight from an incoming osdmap in osdmap_decode(), both are decoded for each osd, i.e., map->max_osd times. The ceph_decode_need() check only accounts for sizeof(*map->osd_weight) once. This can potentially result in an out-of-bounds memory access if the incoming message is corrupted such that the max_osd value exceeds the actual content of the osdmap message. This patch fixes the issue by changing the corresponding part in the ceph_decode_need() check to account for map->max_osd*sizeof(*map->osd_weight).

02

Engine v0.3.0

Risk summary

A malicious or compromised Ceph monitor/OSD server can send a crafted osdmap message with a max_osd value that exceeds the actual message content, causing the kernel client to read beyond the allocated buffer. Because the out-of-bounds read length is effectively unbounded (controlled by the attacker-supplied max_osd), this can result in information disclosure of kernel memory (C:L) or a kernel panic/oops due to hitting unmapped pages (A:H). No privileges on the victim system are required if the attacker controls or can spoof the Ceph cluster endpoint.

Affectednet/ceph/osdmap.c (libceph OSD map decoding)

Vulnerability analysis

The vulnerability is an out-of-bounds read in osdmap_decode() in net/ceph/osdmap.c. When decoding osd_state and osd_weight fields from an incoming osdmap message, both fields are decoded map->max_osd times in a loop. The ceph_decode_need() bounds check prior to this loop incorrectly accounts for only sizeof(*map->osd_weight) (a single entry) rather than map->max_osd * sizeof(*map->osd_weight) (all entries). If a crafted or corrupted osdmap message contains a max_osd value larger than the actual data present, the bounds check passes but subsequent per-OSD decoding reads beyond the end of the message buffer. The fix multiplies the size by map->max_osd to correctly validate that sufficient bytes exist for all OSD weight entries. The attack surface is network-reachable: any kernel configured as a Ceph client that connects to a malicious or MITM'd Ceph monitor could be exploited without any local privileges. The CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H, yielding a base score of 8.2 (High). Confidentiality is Low because the primitive is a constrained out-of-bounds read; Availability is High because a large max_osd value causes the decoder to traverse unmapped pages, resulting in a kernel panic.

03

BranchIntroducedFixed inPatch commit
6.15.36.1.1758713bbc4b2b9
6.125.36.12.91e7187f33c024
6.185.36.18.3348df98d12b15
7.05.37.0.10ee933694645d
6.65.36.6.1410d2dd7e6bb74
mainline5.37.135d0ed82d03e
5.105.35.10.25836a79759a288
5.155.35.15.2093f2575bb7f95