* CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args()
@ 2026-06-24 16:29 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-06-24 16:29 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
libceph: Fix potential null-ptr-deref in decode_choose_args()
A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself
contains a CRUSH map. When decoding this CRUSH map in crush_decode(), an
array of max_buckets CRUSH buckets is decoded, where some indices may
not refer to actual buckets and are therefore set to NULL. The received
CRUSH map may optionally contain choose_args that get decoded in
decode_choose_args(). When decoding a crush_choose_arg_map, a series of
choose_args for different buckets is decoded, with the bucket_index
being read from the incoming message. It is only checked that the bucket
index does not exceed max_buckets, but not that it doesn't point to an
index with a NULL bucket. If a (potentially corrupted) message contains
a crush_choose_arg_map including such a bucket_index, a null pointer
dereference may occur in the subsequent processing when attempting to
access the bucket with the given index.
This patch fixes the issue by extending the affected check. Now, it is
only attempted to access the bucket if it is not NULL.
The Linux kernel CVE team has assigned CVE-2026-52957 to this issue.
Affected and fixed versions
===========================
Fixed in 5.10.258 with commit d55ffad8d422b5d1cc44dad32bd3d25f4471cd9f
Fixed in 5.15.209 with commit 301286c0ccd37d66b0e40786fd35a4f19cdbd88a
Fixed in 6.1.175 with commit 7169f326a23d0f547fcd90e68b72fd387622e126
Fixed in 6.6.141 with commit d7a65a34d2453f8cd3e0cc0e1319740af7e24276
Fixed in 6.12.91 with commit 312ec973efac0efb9b9ed64214235910e9ecbaa8
Fixed in 6.18.33 with commit f2f95e6d4b97e70bb876139b0583fc8079983f85
Fixed in 7.0.10 with commit a20e16ebfe2fa65348eb4b2dc7deac330ce03e9c
Fixed in 7.1 with commit 28b0a2ab8c82d0bbdeb8013029c67c978ce6e4bf
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-52957
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
net/ceph/osdmap.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/d55ffad8d422b5d1cc44dad32bd3d25f4471cd9f
https://git.kernel.org/stable/c/301286c0ccd37d66b0e40786fd35a4f19cdbd88a
https://git.kernel.org/stable/c/7169f326a23d0f547fcd90e68b72fd387622e126
https://git.kernel.org/stable/c/d7a65a34d2453f8cd3e0cc0e1319740af7e24276
https://git.kernel.org/stable/c/312ec973efac0efb9b9ed64214235910e9ecbaa8
https://git.kernel.org/stable/c/f2f95e6d4b97e70bb876139b0583fc8079983f85
https://git.kernel.org/stable/c/a20e16ebfe2fa65348eb4b2dc7deac330ce03e9c
https://git.kernel.org/stable/c/28b0a2ab8c82d0bbdeb8013029c67c978ce6e4bf
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-06-24 16:33 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-24 16:29 CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.