CVE-2026-52955
published 2026-06-24CVE-2026-52955: In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crush_decode() A message of type…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.39%
30.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
libceph: Fix potential out-of-bounds access in crush_decode()
A message of type CEPH_MSG_OSD_MAP containing a crush map with at least
one bucket has two fields holding the bucket algorithm. If the values
in these two fields differ, an out-of-bounds access can occur. This is
the case because the first algorithm field (alg) is used to allocate
the correct amount of memory for a bucket of this type, while the second
algorithm field inside the bucket (b->alg) is used in the subsequent
processing.
This patch fixes the issue by adding a check that compares alg and
b->alg and aborts the processing in case they differ. Furthermore,
b->alg is set to 0 in this case, because the destruction of the crush
map also uses this field to determine the bucket type, which can again
result in an out-of-bounds access when trying to free the memory pointed
to by the fields of the bucket. To correctly free the memory allocated
for the bucket in such a case, the corresponding call to kfree is moved
from the algorithm-specific crush_destroy_bucket functions to the
generic crush_destroy_bucket().
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= f24e9980eb860d8600cbe5ef3d2fd9295320d229 < 6e70ef53e818c53eab28d7b0026b7fd03dddaba5 | 6e70ef53e818c53eab28d7b0026b7fd03dddaba5 |
| linux | linux | >= f24e9980eb860d8600cbe5ef3d2fd9295320d229 < ebe76d58a48a48031b98543d86c4cd30a825b622 | ebe76d58a48a48031b98543d86c4cd30a825b622 |
| linux | linux | >= f24e9980eb860d8600cbe5ef3d2fd9295320d229 < 3f42508191e129ee6b5ea96578d5cab14f2a013a | 3f42508191e129ee6b5ea96578d5cab14f2a013a |
| linux | linux | >= f24e9980eb860d8600cbe5ef3d2fd9295320d229 < ea0d42137f0c06da71e37ffc647aab4c5309599a | ea0d42137f0c06da71e37ffc647aab4c5309599a |
| linux | linux | >= f24e9980eb860d8600cbe5ef3d2fd9295320d229 < cceb10023e76bc89f3fe9238ebd0ccab0fc7c7c5 | cceb10023e76bc89f3fe9238ebd0ccab0fc7c7c5 |
| linux | linux | >= f24e9980eb860d8600cbe5ef3d2fd9295320d229 < 0f3604cbe4df14c5e58288ac9f57511e726a222d | 0f3604cbe4df14c5e58288ac9f57511e726a222d |
| linux | linux | >= f24e9980eb860d8600cbe5ef3d2fd9295320d229 < fb176a99e4c1a5a8448a83d83d3606203ba81faa | fb176a99e4c1a5a8448a83d83d3606203ba81faa |
| linux | linux | >= f24e9980eb860d8600cbe5ef3d2fd9295320d229 < 4c79fc2d598694bda845b46229c9d48b65042970 | 4c79fc2d598694bda845b46229c9d48b65042970 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 2.6.34.1 < 5.10.258 | 5.10.258 |
| linux | linux_kernel | >= 5.11 < 5.15.209 | 5.15.209 |
| linux | linux_kernel | >= 5.16 < 6.1.175 | 6.1.175 |
| linux | linux_kernel | >= 6.13 < 6.18.33 | 6.18.33 |
| linux | linux_kernel | >= 6.19 < 7.0.10 | 7.0.10 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: libceph: Fix potential out-of-bounds access in crush_decode()
vendor_redhat·2026-06-24·CVSS 7.0
CVE-2026-52955 [HIGH] CWE-131 kernel: libceph: Fix potential out-of-bounds access in crush_decode()
kernel: libceph: Fix potential out-of-bounds access in crush_decode()
A flaw was found in the `libceph` component of the Linux kernel. A remote attacker could send a specially crafted `CEPH_MSG_OSD_MAP` message where two internal fields, `alg` and `b->alg`, contain differing bucket algorithm values. This discrepancy can lead to an out-of-bounds memory access during processing or memory deallocation, potentially causing a system crash and resulting in a Denial of Service (DoS).
Package: kernel (Red Hat Enterprise Linux 10) - Affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Affected
Package: kernel (Red Hat Enterprise Linux 8) - Affected
Package: kernel-rt (Red
VulDB
Linux Kernel up to 7.0.9 libceph crush_decode alg out-of-bounds (WID-SEC-2026-2077)
vuldb·2026-06-29·CVSS 9.8
CVE-2026-52955 [CRITICAL] Linux Kernel up to 7.0.9 libceph crush_decode alg out-of-bounds (WID-SEC-2026-2077)
A vulnerability classified as critical has been found in Linux Kernel up to 7.0.9. This affects the function crush_decode of the component libceph. This manipulation of the argument alg causes out-of-bounds read.
The identification of this vulnerability is CVE-2026-52955. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
GHSA
In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crush_decode() A message of type CEPH_MSG_OSD_MAP containing a crush map with at le
ghsa_unreviewed·2026-06-24
CVE-2026-52955 In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crush_decode() A message of type CEPH_MSG_OSD_MAP containing a crush map with at le
In the Linux kernel, the following vulnerability has been resolved:
libceph: Fix potential out-of-bounds access in crush_decode()
A message of type CEPH_MSG_OSD_MAP containing a crush map with at least
one bucket has two fields holding the bucket algorithm. If the values
in these two fields differ, an out-of-bounds access can occur. This is
the case because the first algorithm field (alg) is used to allocate
the correct amount of memory for a bucket of this type, while the second
algorithm field inside the bucket (b->alg) is used in the subsequent
processing.
This patch fixes the issue by adding a check that compares alg and
b->alg and aborts the processing in case they differ. Furthermore,
b->alg is set to 0 in this case, because the destruction of the crush
map also uses this field to
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0f3604cbe4df14c5e58288ac9f57511e726a222dhttps://git.kernel.org/stable/c/3f42508191e129ee6b5ea96578d5cab14f2a013ahttps://git.kernel.org/stable/c/4c79fc2d598694bda845b46229c9d48b65042970https://git.kernel.org/stable/c/6e70ef53e818c53eab28d7b0026b7fd03dddaba5https://git.kernel.org/stable/c/cceb10023e76bc89f3fe9238ebd0ccab0fc7c7c5https://git.kernel.org/stable/c/ea0d42137f0c06da71e37ffc647aab4c5309599ahttps://git.kernel.org/stable/c/ebe76d58a48a48031b98543d86c4cd30a825b622https://git.kernel.org/stable/c/fb176a99e4c1a5a8448a83d83d3606203ba81faahttps://access.redhat.com/security/cve/CVE-2026-52955https://bugzilla.redhat.com/show_bug.cgi?id=2492328https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52955.json
2026-06-24
Published