๐Ÿ” CVE Alert

CVE-2026-68156

CRITICAL 9.8

libceph: refresh auth->authorizer_buf{,_len} after authorizer update

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authorizer_buf{,_len} after authorizer update ceph_x_create_authorizer() caches au->buf->vec.iov_base and au->buf->vec.iov_len in struct ceph_auth_handshake. These cached values are then used by the messenger connect code when sending the authorizer. ceph_x_update_authorizer() can rebuild the authorizer when a newer service ticket is available. If the rebuilt authorizer no longer fits in the existing buffer, ceph_x_build_authorizer() drops its reference to au->buf and allocates a new one. If this is the final reference, ceph_buffer_put() frees the old ceph_buffer and its vec.iov_base, but auth->authorizer_buf still points at that freed memory. A subsequent msgr1 reconnect can therefore queue the stale pointer and trigger a KASAN slab-use-after-free in _copy_from_iter() while tcp_sendmsg() copies the authorizer. Refresh auth->authorizer_buf and auth->authorizer_buf_len after a successful authorizer rebuild so the messenger sends the current buffer.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 10, 2026
Last Updated Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
0bed9b5c523d577378b6f83eab5835fe30c27208 < 2334e9997308305ee4fd508fdfe6086c4150ed60 0bed9b5c523d577378b6f83eab5835fe30c27208 < 79a273df64238a4ade8b709689a78589f755b8ef 0bed9b5c523d577378b6f83eab5835fe30c27208 < 26f814187abceee90dbb29a02133adb4786fbb13 0bed9b5c523d577378b6f83eab5835fe30c27208 < 9d37aec9ffe4e743dabc3f84502e9723e17a30d4 0bed9b5c523d577378b6f83eab5835fe30c27208 < 75e82e8944ac1efe9fdb88bd2f14d9a031282bdf 0bed9b5c523d577378b6f83eab5835fe30c27208 < 0060ec912292a550198d8d18ac95b433c92a7091 0bed9b5c523d577378b6f83eab5835fe30c27208 < 5ecfcd5c05866f185357700b81b461dae4f5ebb2 0bed9b5c523d577378b6f83eab5835fe30c27208 < 937d61f86d377a3aa578adae7a3dfcecdddf9d89 29c65a277a64645af853e8c9a9b3dda0ddc421e0 d2c7223497cf8228416c70e3f4238ddd6c5bdf3c 3.4.50 < 3.5 3.9.7 < 3.10
Linux / Linux
3.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/2334e9997308305ee4fd508fdfe6086c4150ed60 git.kernel.org: https://git.kernel.org/stable/c/79a273df64238a4ade8b709689a78589f755b8ef git.kernel.org: https://git.kernel.org/stable/c/26f814187abceee90dbb29a02133adb4786fbb13 git.kernel.org: https://git.kernel.org/stable/c/9d37aec9ffe4e743dabc3f84502e9723e17a30d4 git.kernel.org: https://git.kernel.org/stable/c/75e82e8944ac1efe9fdb88bd2f14d9a031282bdf git.kernel.org: https://git.kernel.org/stable/c/0060ec912292a550198d8d18ac95b433c92a7091 git.kernel.org: https://git.kernel.org/stable/c/5ecfcd5c05866f185357700b81b461dae4f5ebb2 git.kernel.org: https://git.kernel.org/stable/c/937d61f86d377a3aa578adae7a3dfcecdddf9d89