KernelScan.io

CRITICAL Introduced in 2.6.34

libceph CrushBucket OOB

CVE-2026-68154

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: libceph: reject zero bucket types in crush_decode CRUSH bucket type 0 is reserved for devices. The mapper relies on that invariant and uses type 0 to identify leaf devices. If crush_decode() accepts a bucket with type 0, a malformed CRUSH map can make the mapper treat a negative bucket ID as a device and pass it to is_out(), which then indexes the OSD weight array with a negative value. Reject zero bucket types while decoding the CRUSH map so the invalid state never reaches the mapper.

02

Engine v0.6.0

Risk summary

Systems using the kernel Ceph client are at risk when connected to a malicious or compromised Ceph monitor. A malformed CRUSH map causes the kernel to access the OSD weight array with an attacker-controlled negative offset, leading to a kernel crash. No client-side privileges are required.

Affectednet/ceph/osdmap.c (libceph)

Vulnerability analysis

The Ceph client's CRUSH map decoder incorrectly accepts bucket type 0, which is reserved for devices. A malicious or compromised Ceph monitor can supply a CRUSH map containing a type-0 bucket with a negative ID, causing the mapper to treat that ID as a device index and access the OSD weight array out of bounds. The fix rejects type-0 buckets during decoding so the invalid state never reaches the mapper. Any system using the kernel Ceph client is affected; the attack requires no client-side privileges, only a malicious or MITM'd Ceph monitor sending the malformed map.

03

BranchIntroducedFixed inPatch commit
5.102.6.345.10.265952ca5dc9991
5.152.6.345.15.216146461f09565
6.12.6.346.1.18380fc40e11cda
6.62.6.346.6.148b8a9fb6bf806
6.182.6.346.18.423b2f1937f5fc
7.12.6.347.1.670998f91030e
mainline2.6.347.205f902842233
6.122.6.346.12.101826cd1de5802