From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8CB9E30EF89 for ; Wed, 24 Jun 2026 16:33:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782318783; cv=none; b=otuGu7SiiEyC92iOzZLfSmCmqxB8H1EoKNyelngnfoQExHjLzs9kWGKE2ZThH0uA7R1rZuPg5caEHzqUQAM4et/aBmuuqRK5hGwNbgp5DE3v9vjjYHZjzortZTB36cH5f45J0NmZhOzQHD50Ttu2KZQlDte4dswOAOjC3P1Z5xg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782318783; c=relaxed/simple; bh=DGYddaNvB2cvnXD3JNQVPmi4FYhxCsaH9CaPqmipIew=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=d/29szEhMwCQYE7/Pgu+lg2tX0pjMQgBx2rnaf4/5dWkASntDQXuDlYJN0+ZccfAGlFzquiKUZo+arPC4y5x38omNVyOVqni28ZfMLIeaz+RyfwpGCFiW1+ZotH7HZV/4D6i9HnM6pNn6HF7AdSqih8dj6iDEVe+otqS2LXqYRg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=oKvKgczX; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="oKvKgczX" Received: by smtp.kernel.org (Postfix) with ESMTPSA id A23B51F000E9; Wed, 24 Jun 2026 16:33:01 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1782318782; bh=UCmkhzLsdQn6J6CvvivxM3wDZi2gbj4T1zmbz4Vgbhw=; h=From:To:Cc:Subject:Date:Reply-To; b=oKvKgczXZrAzYyir/hP7Rj+Jki5h/W+OYnzCetb1Es/wGnHg3Wuo8JS8eaRzUxF2C 7XmTHiAeUiijhA7L2JeoKskqxFCQP6f7Zu18Bzxpg3N3N7sSlrFdQTgl2pZ2L/HPT3 l5NddPIEU6uS11ae7Joxu/Is3g23OiKyKd+Q3d2U= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() Date: Wed, 24 Jun 2026 17:29:39 +0100 Message-ID: <2026062435-CVE-2026-52955-77f4@gregkh> X-Mailer: git-send-email 2.54.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3547; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=mwEvN5wHTcKkFxB8+QyfaIBb4fAkq8pxFpYglf8TT4Q=; b=owGbwMvMwCRo6H6F97bub03G02pJDFk2rO+n3V9izqaqP4stUzLvscWNCdNfMLWcXWSYL9ghK R0yg6mnI5aFQZCJQVZMkeXLNp6j+ysOKXoZ2p6GmcPKBDKEgYtTACZy8AvDgmUpNhM3FH43dVw/ V7DHrG+9+0PWNob5rpeZQrUbX3JWT9Ywkuvbquoz53QjAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crush_decode() A message of type CEPH_MSG_OSD_MAP containing a crush map with at least one bucket has two fields holding the bucket algorithm. If the values in these two fields differ, an out-of-bounds access can occur. This is the case because the first algorithm field (alg) is used to allocate the correct amount of memory for a bucket of this type, while the second algorithm field inside the bucket (b->alg) is used in the subsequent processing. This patch fixes the issue by adding a check that compares alg and b->alg and aborts the processing in case they differ. Furthermore, b->alg is set to 0 in this case, because the destruction of the crush map also uses this field to determine the bucket type, which can again result in an out-of-bounds access when trying to free the memory pointed to by the fields of the bucket. To correctly free the memory allocated for the bucket in such a case, the corresponding call to kfree is moved from the algorithm-specific crush_destroy_bucket functions to the generic crush_destroy_bucket(). The Linux kernel CVE team has assigned CVE-2026-52955 to this issue. Affected and fixed versions =========================== Fixed in 5.10.258 with commit 6e70ef53e818c53eab28d7b0026b7fd03dddaba5 Fixed in 5.15.209 with commit ebe76d58a48a48031b98543d86c4cd30a825b622 Fixed in 6.1.175 with commit 3f42508191e129ee6b5ea96578d5cab14f2a013a Fixed in 6.6.141 with commit ea0d42137f0c06da71e37ffc647aab4c5309599a Fixed in 6.12.91 with commit cceb10023e76bc89f3fe9238ebd0ccab0fc7c7c5 Fixed in 6.18.33 with commit 0f3604cbe4df14c5e58288ac9f57511e726a222d Fixed in 7.0.10 with commit fb176a99e4c1a5a8448a83d83d3606203ba81faa Fixed in 7.1 with commit 4c79fc2d598694bda845b46229c9d48b65042970 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-52955 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/ceph/crush/crush.c net/ceph/osdmap.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/6e70ef53e818c53eab28d7b0026b7fd03dddaba5 https://git.kernel.org/stable/c/ebe76d58a48a48031b98543d86c4cd30a825b622 https://git.kernel.org/stable/c/3f42508191e129ee6b5ea96578d5cab14f2a013a https://git.kernel.org/stable/c/ea0d42137f0c06da71e37ffc647aab4c5309599a https://git.kernel.org/stable/c/cceb10023e76bc89f3fe9238ebd0ccab0fc7c7c5 https://git.kernel.org/stable/c/0f3604cbe4df14c5e58288ac9f57511e726a222d https://git.kernel.org/stable/c/fb176a99e4c1a5a8448a83d83d3606203ba81faa https://git.kernel.org/stable/c/4c79fc2d598694bda845b46229c9d48b65042970