๐Ÿ” CVE Alert

CVE-2026-68159

CRITICAL 9.8

libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to overflow the allocation; it does not bound it to CEPH_PG_MAX_SIZE. The helper backs both pg_temp and pg_upmap decoding, and apply_upmap()/get_temp_osds() later copy the decoded list into the fixed-size on-stack array struct ceph_osds.osds[CEPH_PG_MAX_SIZE]. A monitor that sends an OSDMap with a pg_temp/pg_upmap entry longer than 32 thus causes a stack out-of-bounds write. An OSD set for a single PG can never exceed CEPH_PG_MAX_SIZE, so reject longer entries at decode time. The bound is well below the old overflow threshold, so it also covers the allocation-size overflow the previous check guarded against. BUG: KASAN: stack-out-of-bounds in ceph_pg_to_up_acting_osds Write of size 4 ... by task exploit kasan_report (mm/kasan/report.c:595) ceph_pg_to_up_acting_osds (net/ceph/osdmap.c:2617 net/ceph/osdmap.c:2833) calc_target (net/ceph/osd_client.c:1638) __submit_request (net/ceph/osd_client.c:2394) ceph_osdc_start_request (net/ceph/osd_client.c:2490) ceph_osdc_call (net/ceph/osd_client.c:5164) rbd_dev_image_probe (drivers/block/rbd.c:6899) do_rbd_add (drivers/block/rbd.c:7138) ... kernel BUG at net/ceph/osdmap.c:2670! [ idryomov: do the same in __decode_pg_upmap_items() ]

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 10, 2026
Last Updated Aug 23, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
a303bb0e58345fe9f7ab2f82b90266f2b5036058 < 66eec4af1e080b695229c9a20635648a6d12fedf a303bb0e58345fe9f7ab2f82b90266f2b5036058 < 4daf06456677177f2a6044729abac59c1b49e87b a303bb0e58345fe9f7ab2f82b90266f2b5036058 < d5650ddbd4d42c1a916c8fe1a4c4cb573ef810a1 a303bb0e58345fe9f7ab2f82b90266f2b5036058 < 42bc06c67d94d5f2a6b33294b0c4b07d8a47c515 a303bb0e58345fe9f7ab2f82b90266f2b5036058 < ebdf4b4f3b1474079980a2e5cd79ad65fb54db57 a303bb0e58345fe9f7ab2f82b90266f2b5036058 < 590b07ceea138d49c9b64f65d263aa902d3b4730 a303bb0e58345fe9f7ab2f82b90266f2b5036058 < e36663145abd7024f0281dfb22fdef65f185845b a303bb0e58345fe9f7ab2f82b90266f2b5036058 < 9f00f9cf2be293efe899db67dc5272e3a9c62717
Linux / Linux
4.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/66eec4af1e080b695229c9a20635648a6d12fedf git.kernel.org: https://git.kernel.org/stable/c/4daf06456677177f2a6044729abac59c1b49e87b git.kernel.org: https://git.kernel.org/stable/c/d5650ddbd4d42c1a916c8fe1a4c4cb573ef810a1 git.kernel.org: https://git.kernel.org/stable/c/42bc06c67d94d5f2a6b33294b0c4b07d8a47c515 git.kernel.org: https://git.kernel.org/stable/c/ebdf4b4f3b1474079980a2e5cd79ad65fb54db57 git.kernel.org: https://git.kernel.org/stable/c/590b07ceea138d49c9b64f65d263aa902d3b4730 git.kernel.org: https://git.kernel.org/stable/c/e36663145abd7024f0281dfb22fdef65f185845b git.kernel.org: https://git.kernel.org/stable/c/9f00f9cf2be293efe899db67dc5272e3a9c62717