CVE-2025-68283 — Improper Validation of Specified Index, Position, or Offset in Input in Linux
CWE-1285 — Improper Validation of Specified Index, Position, or Offset in Input37 documents8 sources
Severity
7.2HIGHOSV
OSV3.2
No vectorEPSS
0.1%
top 84.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
libceph: replace BUG_ON with bounds check for map->max_osd
OSD indexes come from untrusted network packets. Boundary checks are
added to validate these against map->max_osd.
[ idryomov: drop BUG_ON in ceph_get_primary_affinity(), minor cosmetic
edits ]
Affected Packages7 packages
▶CVEListV5linux/linuxf24e9980eb860d8600cbe5ef3d2fd9295320d229 — 57f5fbae9f1024aba17ff75e00433324115c548a+5