cbcvebase.
CVE-2026-22990
published 2026-01-23

CVE-2026-22990: In the Linux kernel, the following vulnerability has been resolved: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() If the osdmap is…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.34%
26.3th percentile
In the Linux kernel, the following vulnerability has been resolved: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() If the osdmap is (maliciously) corrupted such that the incremental osdmap epoch is different from what is expected, there is no need to BUG. Instead, just declare the incremental osdmap to be invalid.

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= f24e9980eb860d8600cbe5ef3d2fd9295320d229 < 9aa0b0c14cefece078286d78b97d4c09685e372d9aa0b0c14cefece078286d78b97d4c09685e372d
linuxlinux>= f24e9980eb860d8600cbe5ef3d2fd9295320d229 < 4b106fbb1c7b841cd402abd83eb2447164c799ea4b106fbb1c7b841cd402abd83eb2447164c799ea
linuxlinux>= f24e9980eb860d8600cbe5ef3d2fd9295320d229 < 6afd2a4213524bc742b709599a3663aeaf77193c6afd2a4213524bc742b709599a3663aeaf77193c
linuxlinux>= f24e9980eb860d8600cbe5ef3d2fd9295320d229 < d3613770e2677683e65d062da5e31f48c409abe9d3613770e2677683e65d062da5e31f48c409abe9
linuxlinux>= f24e9980eb860d8600cbe5ef3d2fd9295320d229 < 6c6cec3db3b418c4fdf815731bc39e46dff75e1b6c6cec3db3b418c4fdf815731bc39e46dff75e1b
linuxlinux>= f24e9980eb860d8600cbe5ef3d2fd9295320d229 < 6348d70af847b79805374fe628d3809a63fd7df36348d70af847b79805374fe628d3809a63fd7df3
linuxlinux>= f24e9980eb860d8600cbe5ef3d2fd9295320d229 < e00c3f71b5cf75681dbd74ee3f982a99cb690c2be00c3f71b5cf75681dbd74ee3f982a99cb690c2b
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 2.6.34.1 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16 < 6.1.1616.1.161
linuxlinux_kernel>= 6.13 < 6.18.66.18.6
linuxlinux_kernel>= 6.2 < 6.6.1216.6.121
linuxlinux_kernel>= 6.7 < 6.12.666.12.66
ubuntulinux
ubuntulinux-aws

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.