KernelScan.io

HIGH Introduced in 5.8

libceph CrushType Deref

CVE-2026-68157

CVSS 7.5 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: libceph: guard missing CRUSH type name lookup Localized read selection can walk a parent bucket whose name exists in the CRUSH map while its type has no matching entry in type_names. get_immediate_parent() then dereferences a NULL type_cn and passes an invalid pointer into strcmp(), causing a null-ptr-deref. Skip such malformed parent buckets unless both the bucket name and type name metadata are present. This keeps malformed hierarchy data from crashing locality lookup and safely falls back to "not local". [ idryomov: add WARN_ON_ONCE ]

02

Engine v0.6.0

Risk summary

A Ceph client kernel can be crashed by a malformed CRUSH map received from a Ceph monitor. The vulnerability is a NULL pointer dereference triggered during localized read selection when a parent bucket's type has no matching entry in the type_names list. Any Linux system acting as a Ceph client (CephFS mount or RBD usage) connected to a compromised or malicious monitor is at risk of a kernel panic, resulting in full system unavailability.

Affectednet/ceph/osdmap.c (libceph)

Vulnerability analysis

When a Ceph client processes a CRUSH map that contains a parent bucket whose name is present but whose type metadata is missing, the local read selection code looks up the type name, receives a NULL pointer, and dereferences it — causing a kernel panic. The malformed map data arrives from the Ceph monitor over the network as part of the normal OSD map distribution; no client-side privileges are required to trigger the crash, only an active read operation that exercises the local selection logic. The fix adds a check after the type name lookup and skips any bucket whose type name is missing, safely falling back to treating the data as non-local instead of crashing. This vulnerability is reachable only on systems running a Ceph client (CephFS or RBD) connected to a Ceph cluster where the monitor distributes a malformed or maliciously crafted CRUSH map.

03

BranchIntroducedFixed inPatch commit
6.15.86.1.1836a4b75d90f0c
6.65.86.6.148c46d82c47afc
6.125.86.12.1013767c9f0c1bb
mainline5.87.2bbeae12fda33
6.185.86.18.424716a64b7cc2
5.155.85.15.2168ff579ac03d6
5.105.85.10.265cbfcba275326
7.15.87.1.6db9cc9fd9660