KernelScan.io

HIGH Introduced in 2.6.34

libceph MonMap Panic

CVE-2026-68155

CVSS 7.5 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a monitor to the client. This monmap contains information about the existing monitors in the cluster. Currently, a monmap indicating that there are zero monitors in the cluster is treated as valid. However, it is impossible to have zero monitors in the cluster and still receive a valid monmap from a monitor. Therefore, such a monmap must be corrupted and should be treated as invalid. Furthermore, a monmap with a monitor count of zero can subsequently crash the client when attempting to open a session with a monitor in __open_session(). This happens because the "BUG_ON(monc->monmap->num_mon < 1)" assertion in pick_new_mon() is triggered. This patch extends a check in ceph_monmap_decode() to also reject arriving mon_maps with num_mon == 0 rather than only with num_mon > CEPH_MAX_MON. [ idryomov: drop "log output for unusual values of num_mon" part ]

02

Engine v0.6.0

Risk summary

A Ceph client kernel receiving a crafted monitor map (monmap) with a zero-monitor count from a malicious or compromised Ceph monitor will trigger a kernel BUG_ON assertion and panic. Any system acting as a Ceph client is at risk if the monitor it connects to is malicious or the connection is subject to a man-in-the-middle attack. The impact is a full system crash with no data confidentiality or integrity compromise.

Affectednet/ceph/mon_client.c (libceph)

Vulnerability analysis

The Ceph monitor map decoder accepts a map that advertises zero monitors as valid, even though such a map cannot legitimately come from a real Ceph monitor. When the client later tries to open a session with a monitor, an internal assertion detects the impossible zero-monitor state and triggers a kernel panic. The fix adds a simple validation check so that any map with a zero-monitor count is rejected as invalid before it can be installed. The vulnerable code path is reached when a Ceph client receives a monitor map message over the network from a Ceph monitor, meaning a malicious or compromised monitor—or an attacker who can intercept the client-to-monitor traffic—can crash the client kernel with no privileges on the target system.

03

BranchIntroducedFixed inPatch commit
5.152.6.345.15.216caf082ef8609
6.62.6.346.6.1480591a15815b4
7.12.6.347.1.63b249546f59c
mainline2.6.347.240480eee361e
6.122.6.346.12.101cd0d41bc5696
6.12.6.346.1.183e3ccd4ecab09
6.182.6.346.18.42e67e8b694872