CRITICAL
libceph Authorizer UAF
CVE-2026-68156
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI8.1HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authorizer_buf{,_len} after authorizer update ceph_x_create_authorizer() caches au->buf->vec.iov_base and au->buf->vec.iov_len in struct ceph_auth_handshake. These cached values are then used by the messenger connect code when sending the authorizer. ceph_x_update_authorizer() can rebuild the authorizer when a newer service ticket is available. If the rebuilt authorizer no longer fits in the existing buffer, ceph_x_build_authorizer() drops its reference to au->buf and allocates a new one. If this is the final reference, ceph_buffer_put() frees the old ceph_buffer and its vec.iov_base, but auth->authorizer_buf still points at that freed memory. A subsequent msgr1 reconnect can therefore queue the stale pointer and trigger a KASAN slab-use-after-free in _copy_from_iter() while tcp_sendmsg() copies the authorizer. Refresh auth->authorizer_buf and auth->authorizer_buf_len after a successful authorizer rebuild so the messenger sends the current buffer.
02KernelScan AI Analysis
Risk summary
A use-after-free in the Ceph client authentication code allows a malicious or compromised Ceph server to trigger kernel memory corruption by rotating service tickets. The stale buffer pointer is used during reconnection, potentially leaking freed kernel memory over the network or causing a kernel crash. Any system running a Ceph kernel client connected to an untrusted or compromised server is at risk.
Vulnerability analysis
The Ceph client authentication code caches a pointer to the authorizer buffer when the authorizer is first created. When a service ticket is rotated, the authorizer is rebuilt and the old buffer may be freed and replaced with a larger one, but the cached pointer is not refreshed. A subsequent reconnection then reads from the freed memory, sending its contents over the network or crashing the kernel. The fix refreshes the cached pointer and length after every successful authorizer rebuild so the messenger always references the current buffer. This is reachable by a malicious or compromised Ceph server over the network; the client requires no special privileges beyond being configured to connect to the server.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.6 | — | 6.6.148 | 0060ec912292 |
| 3.4 | 3.4.50 | 3.5 | 2334e9997308 |
| 5.10 | — | 5.10.265 | 26f814187abc |
| 5.15 | — | 5.15.216 | 9d37aec9ffe4 |
| 6.1 | — | 6.1.183 | 75e82e8944ac |
| 6.12 | — | 6.12.101 | 5ecfcd5c0586 |
| 7.1 | — | 7.1.6 | — |
| mainline | — | 7.2 | — |
| 3.9 | 3.9.7 | 3.10 | 79a273df6423 |
| 6.18 | — | 6.18.42 | 937d61f86d37 |