CVE-2026-52958
published 2026-06-24CVE-2026-52958: In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdmap_decode() When decoding osd_state and…
PriorityP348critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.54%
42.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
libceph: Fix potential out-of-bounds access in osdmap_decode()
When decoding osd_state and osd_weight from an incoming osdmap in
osdmap_decode(), both are decoded for each osd, i.e., map->max_osd
times. The ceph_decode_need() check only accounts for
sizeof(*map->osd_weight) once. This can potentially result in an
out-of-bounds memory access if the incoming message is corrupted such
that the max_osd value exceeds the actual content of the osdmap message.
This patch fixes the issue by changing the corresponding part in the
ceph_decode_need() check to account for
map->max_osd*sizeof(*map->osd_weight).
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= dcbc919a5dc8c2629684a113a90c0b6fe10c3462 < 36a79759a288961b1ff28a68ec2d1f56f6848098 | 36a79759a288961b1ff28a68ec2d1f56f6848098 |
| linux | linux | >= dcbc919a5dc8c2629684a113a90c0b6fe10c3462 < 3f2575bb7f955d42569d96c3e04fa958a0dcf4b4 | 3f2575bb7f955d42569d96c3e04fa958a0dcf4b4 |
| linux | linux | >= dcbc919a5dc8c2629684a113a90c0b6fe10c3462 < 8713bbc4b2b9ad78f803978e54b7e49dd21bd9be | 8713bbc4b2b9ad78f803978e54b7e49dd21bd9be |
| linux | linux | >= dcbc919a5dc8c2629684a113a90c0b6fe10c3462 < 0d2dd7e6bb74fd7712aa73457a4a821906c6863a | 0d2dd7e6bb74fd7712aa73457a4a821906c6863a |
| linux | linux | >= dcbc919a5dc8c2629684a113a90c0b6fe10c3462 < e7187f33c02488697ec0d01d82bf7a3f8deaba8f | e7187f33c02488697ec0d01d82bf7a3f8deaba8f |
| linux | linux | >= dcbc919a5dc8c2629684a113a90c0b6fe10c3462 < 48df98d12b15360cd56af5c1f460307b340c1197 | 48df98d12b15360cd56af5c1f460307b340c1197 |
| linux | linux | >= dcbc919a5dc8c2629684a113a90c0b6fe10c3462 < ee933694645dac062d65fc2743f92bc06fa0db6b | ee933694645dac062d65fc2743f92bc06fa0db6b |
| linux | linux | >= dcbc919a5dc8c2629684a113a90c0b6fe10c3462 < 35d0ed82d03e5ee77ea4f31f20e29562a7721649 | 35d0ed82d03e5ee77ea4f31f20e29562a7721649 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 5.11 < 5.15.209 | 5.15.209 |
| linux | linux_kernel | >= 5.16 < 6.1.175 | 6.1.175 |
| linux | linux_kernel | >= 5.3 < 5.10.258 | 5.10.258 |
| linux | linux_kernel | >= 6.13 < 6.18.33 | 6.18.33 |
| linux | linux_kernel | >= 6.19 < 7.0.10 | 7.0.10 |
| linux | linux_kernel | >= 6.2 < 6.6.141 | 6.6.141 |
| linux | linux_kernel | >= 6.7 < 6.12.91 | 6.12.91 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: libceph: Fix potential out-of-bounds access in osdmap_decode()
vendor_redhat·2026-06-24·CVSS 5.5
CVE-2026-52958 [MEDIUM] CWE-1284 kernel: libceph: Fix potential out-of-bounds access in osdmap_decode()
kernel: libceph: Fix potential out-of-bounds access in osdmap_decode()
A flaw was found in the Linux kernel's `libceph` component. This vulnerability, located within the `osdmap_decode()` function, can lead to an out-of-bounds memory access. A remote attacker could exploit this by sending a specially crafted and corrupted `osdmap` message, where the `max_osd` value exceeds the actual message content. This could potentially result in system instability or other unforeseen impacts due to memory corruption.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linu
GHSA
In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdmap_decode() When decoding osd_state and osd_weight from an incoming osdmap in o
ghsa_unreviewed·2026-06-24
CVE-2026-52958 In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdmap_decode() When decoding osd_state and osd_weight from an incoming osdmap in o
In the Linux kernel, the following vulnerability has been resolved:
libceph: Fix potential out-of-bounds access in osdmap_decode()
When decoding osd_state and osd_weight from an incoming osdmap in
osdmap_decode(), both are decoded for each osd, i.e., map->max_osd
times. The ceph_decode_need() check only accounts for
sizeof(*map->osd_weight) once. This can potentially result in an
out-of-bounds memory access if the incoming message is corrupted such
that the max_osd value exceeds the actual content of the osdmap message.
This patch fixes the issue by changing the corresponding part in the
ceph_decode_need() check to account for
map->max_osd*sizeof(*map->osd_weight).
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0d2dd7e6bb74fd7712aa73457a4a821906c6863ahttps://git.kernel.org/stable/c/35d0ed82d03e5ee77ea4f31f20e29562a7721649https://git.kernel.org/stable/c/36a79759a288961b1ff28a68ec2d1f56f6848098https://git.kernel.org/stable/c/3f2575bb7f955d42569d96c3e04fa958a0dcf4b4https://git.kernel.org/stable/c/48df98d12b15360cd56af5c1f460307b340c1197https://git.kernel.org/stable/c/8713bbc4b2b9ad78f803978e54b7e49dd21bd9behttps://git.kernel.org/stable/c/e7187f33c02488697ec0d01d82bf7a3f8deaba8fhttps://git.kernel.org/stable/c/ee933694645dac062d65fc2743f92bc06fa0db6b
2026-06-24
Published