CRITICAL Introduced in 4.11
libceph CrushBucket OOB
CVE-2026-89656
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI8.1HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: libceph: reject buckets with mismatched CRUSH ids crush_decode() stores bucket data by array slot, and the mapper later derives the per-bucket workspace index from the decoded bucket id. A malformed map can therefore make one bucket reuse another bucket's workspace by encoding an id different from -1 - slot. For uniform buckets, the second replica selection expands the source bucket's permutation into that aliased workspace buffer. If the source bucket is larger than the aliased bucket, the write runs past the smaller permutation array and can escape the kvmalloc'd CRUSH workspace. KASAN reports a slab OOB write of 4 bytes in bucket_perm_choose(). Reject buckets whose encoded id does not match their array slot. Valid CRUSH maps already use the canonical negative id corresponding to the bucket slot, so this restores the invariant expected by work->work[-1 - in->id] without changing valid map behavior.
02KernelScan AI Analysis
Risk summary
A malformed Ceph CRUSH map received over the network can cause an out-of-bounds heap write in the kernel Ceph client, potentially leading to kernel memory corruption, information disclosure, or a system crash. Any Linux system acting as a Ceph client (cephfs mount or RBD) is at risk if an attacker can inject a crafted OSD map via a compromised monitor or MITM position.
Vulnerability analysis
The Ceph CRUSH map decoder stores bucket data by array slot, but the placement mapper later indexes each bucket's workspace using the decoded bucket id. A malformed map can encode a bucket id that does not match its slot, causing two buckets to alias the same workspace buffer. When a larger uniform bucket expands its permutation into the smaller aliased workspace, the write overflows the allocation and corrupts adjacent kernel heap memory. The fix rejects any bucket whose encoded id does not equal the expected id for its array slot, restoring the invariant the mapper relies on without affecting valid maps. The vulnerable path is reached when a kernel Ceph client receives and decodes an OSD map from the network, so an attacker who controls a Ceph monitor or can intercept the Ceph protocol can trigger this on any connected client without local privileges.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.18 | 4.11 | 6.18.50 | 00562ccd4e88 |
| 6.12 | 4.11 | 6.12.109 | 3516a4131c4e |
| mainline | 4.11 | 7.3-rc1 | 3cde4a830230 |
| 6.1 | 4.11 | 6.1.188 | 4aeb93daadf3 |
| 6.6 | 4.11 | 6.6.157 | 6e5c6ce252b1 |
| 7.2 | 4.11 | 7.2.4 | 79900d978158 |
| 5.15 | 4.11 | 5.15.221 | baad5875fdd2 |
| 5.10 | 4.11 | 5.10.270 | ee59040d6ed1 |