cbcvebase.
CVE-2026-22984
published 2026-01-23

CVE-2026-22984: In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in handle_auth_done() Perform an explicit…

PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.35%
27.8th percentile
In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in handle_auth_done() Perform an explicit bounds check on payload_len to avoid a possible out-of-bounds access in the callout. [ idryomov: changelog ]

Affected

49 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= cd1a677cad994021b19665ed476aea63f5d54f31 < 194cfe2af4d2a1de599d39dad636b47c2f6c2c96194cfe2af4d2a1de599d39dad636b47c2f6c2c96
linuxlinux>= cd1a677cad994021b19665ed476aea63f5d54f31 < 79fe3511db416d2f2edcfd93569807cb02736e5e79fe3511db416d2f2edcfd93569807cb02736e5e
linuxlinux>= cd1a677cad994021b19665ed476aea63f5d54f31 < ef208ea331ef688729f64089b895ed1b49e842e3ef208ea331ef688729f64089b895ed1b49e842e3
linuxlinux>= cd1a677cad994021b19665ed476aea63f5d54f31 < 2802ef3380fa8c4a08cda51ec1f085b1a712e9e22802ef3380fa8c4a08cda51ec1f085b1a712e9e2
linuxlinux>= cd1a677cad994021b19665ed476aea63f5d54f31 < 2d653bb63d598ae4b096dd678744bdcc34ee89e82d653bb63d598ae4b096dd678744bdcc34ee89e8
linuxlinux>= cd1a677cad994021b19665ed476aea63f5d54f31 < 818156caffbf55cb4d368f9c3cac64e458fb49c9818156caffbf55cb4d368f9c3cac64e458fb49c9
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 5.11 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16 < 6.1.1616.1.161
linuxlinux_kernel>= 6.13 < 6.18.66.18.6
linuxlinux_kernel>= 6.2 < 6.6.1216.6.121
linuxlinux_kernel>= 6.7 < 6.12.666.12.66
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15
ubuntulinux-azure-6.17

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.