KernelScan.io

CRITICAL Introduced in 4.13

libceph OSDMap OOB

CVE-2026-68159

CVSS 9.8 / 10.0 KernelScan AI

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

01

In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to overflow the allocation; it does not bound it to CEPH_PG_MAX_SIZE. The helper backs both pg_temp and pg_upmap decoding, and apply_upmap()/get_temp_osds() later copy the decoded list into the fixed-size on-stack array struct ceph_osds.osds[CEPH_PG_MAX_SIZE]. A monitor that sends an OSDMap with a pg_temp/pg_upmap entry longer than 32 thus causes a stack out-of-bounds write. An OSD set for a single PG can never exceed CEPH_PG_MAX_SIZE, so reject longer entries at decode time. The bound is well below the old overflow threshold, so it also covers the allocation-size overflow the previous check guarded against. BUG: KASAN: stack-out-of-bounds in ceph_pg_to_up_acting_osds Write of size 4 ... by task exploit kasan_report (mm/kasan/report.c:595) ceph_pg_to_up_acting_osds (net/ceph/osdmap.c:2617 net/ceph/osdmap.c:2833) calc_target (net/ceph/osd_client.c:1638) __submit_request (net/ceph/osd_client.c:2394) ceph_osdc_start_request (net/ceph/osd_client.c:2490) ceph_osdc_call (net/ceph/osd_client.c:5164) rbd_dev_image_probe (drivers/block/rbd.c:6899) do_rbd_add (drivers/block/rbd.c:7138) ... kernel BUG at net/ceph/osdmap.c:2670! [ idryomov: do the same in __decode_pg_upmap_items() ]

02

Engine v0.6.0

Risk summary

A malicious or compromised Ceph monitor can send a crafted OSDMap containing pg_temp or pg_upmap entries longer than the maximum allowed size. The Ceph client kernel code decodes this without proper bounds checking and later copies the oversized list into a fixed-size stack array, causing a stack out-of-bounds write. Any Linux system acting as a Ceph client (using CephFS or rbd) is at risk; the attack requires no local privileges on the target, only that the client is connected to the malicious monitor.

Affectednet/ceph/osdmap.c (libceph)

Vulnerability analysis

The Ceph client accepts length values from the monitor for certain mapping entries, but it only checks for allocation overflow, not against the hard maximum size allowed by the protocol. Later, when the client copies the decoded list into a small fixed-size array on the kernel stack, an oversized entry writes past the array bounds, corrupting stack memory. The fix enforces the protocol maximum during decoding so that overlong entries are rejected before any copy happens. A malicious or compromised Ceph monitor, or a man-in-the-middle on the monitor connection, can trigger this against any connected client with no local privileges or user interaction required on the target.

03

BranchIntroducedFixed inPatch commit
7.14.137.1.6e36663145abd
mainline4.137.2-rc59f00f9cf2be2