KernelScan.io

CRITICAL

libceph OSDMap Overflow

CVE-2026-68158

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI9.1CRITICAL

01

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix multiplication overflow in decode_new_up_state_weight() If a message of type CEPH_MSG_OSD_MAP contains a (maliciously) corrupted osdmap, out-of-bounds memory accesses may occur in decode_new_up_state_weight(). This happens because the bounds check for the new_state part is based on calculating its length depending on a len value read from the incoming message. This calculation may overflow leading to an incorrect bounds check. Subsequently, out-of-bounds reads may occur when decoding this part. This patch switches the multiplication to use check_mul_overflow() to abort processing the osdmap if an overflow occurred. Therefore, osdmaps/messages containing large values for len that result in a multiplication overflow are treated as invalid. [ idryomov: rename new_state_len -> new_state_item_size, formatting ]

02

Engine v0.6.0

Risk summary

A Ceph kernel client processing a crafted OSD map message from a malicious or compromised server can suffer out-of-bounds memory reads due to an integer overflow in the length calculation. This can leak kernel memory or crash the system. Any product that mounts Ceph storage (rbd or cephfs) and is exposed to an untrusted or compromised Ceph cluster is at risk.

Affectednet/ceph/osdmap.c (libceph)

Vulnerability analysis

When a Ceph client receives an OSD map update from a server, it decodes a section whose total length is computed by multiplying an attacker-controlled count by a per-item size. On 32-bit arithmetic this multiplication can silently overflow, producing a small value that passes the bounds check. The decoder then reads far past the end of the valid message buffer, causing out-of-bounds memory reads that can leak kernel heap data or trigger a panic. The fix replaces the plain multiplication with an overflow-checked operation that rejects the entire OSD map if an overflow is detected. This code path is reached automatically by any kernel Ceph client (rbd or ceph filesystem) when it receives an OSD map message, so a malicious or compromised Ceph monitor or OSD—or a network attacker in a position to inject or tamper with Ceph protocol traffic—can trigger it with no privileges on the client host.

03

BranchIntroducedFixed inPatch commit
3.163.16.393.1705c90e059269
3.103.10.1033.112ceee3b77b83
3.143.14.753.15f6961070c326
3.183.18.393.19143ba49ead77
4.14.1.304.21732d89dfcd7
4.44.4.174.5bee4b5b53e7b
4.64.6.64.798917a499ec7
5.10—5.10.265—
5.15—5.15.216—
6.1—6.1.183—
6.6—6.6.148—
6.12—6.12.101—
6.18—6.18.42—
7.1—7.1.6—
mainline—7.2—
3.123.12.633.13e4473751cc37