All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args()
@ 2026-06-24 16:29 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-06-24 16:29 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

libceph: Fix potential null-ptr-deref in decode_choose_args()

A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself
contains a CRUSH map. When decoding this CRUSH map in crush_decode(), an
array of max_buckets CRUSH buckets is decoded, where some indices may
not refer to actual buckets and are therefore set to NULL. The received
CRUSH map may optionally contain choose_args that get decoded in
decode_choose_args(). When decoding a crush_choose_arg_map, a series of
choose_args for different buckets is decoded, with the bucket_index
being read from the incoming message. It is only checked that the bucket
index does not exceed max_buckets, but not that it doesn't point to an
index with a NULL bucket. If a (potentially corrupted) message contains
a crush_choose_arg_map including such a bucket_index, a null pointer
dereference may occur in the subsequent processing when attempting to
access the bucket with the given index.

This patch fixes the issue by extending the affected check. Now, it is
only attempted to access the bucket if it is not NULL.

The Linux kernel CVE team has assigned CVE-2026-52957 to this issue.


Affected and fixed versions
===========================

	Fixed in 5.10.258 with commit d55ffad8d422b5d1cc44dad32bd3d25f4471cd9f
	Fixed in 5.15.209 with commit 301286c0ccd37d66b0e40786fd35a4f19cdbd88a
	Fixed in 6.1.175 with commit 7169f326a23d0f547fcd90e68b72fd387622e126
	Fixed in 6.6.141 with commit d7a65a34d2453f8cd3e0cc0e1319740af7e24276
	Fixed in 6.12.91 with commit 312ec973efac0efb9b9ed64214235910e9ecbaa8
	Fixed in 6.18.33 with commit f2f95e6d4b97e70bb876139b0583fc8079983f85
	Fixed in 7.0.10 with commit a20e16ebfe2fa65348eb4b2dc7deac330ce03e9c
	Fixed in 7.1 with commit 28b0a2ab8c82d0bbdeb8013029c67c978ce6e4bf

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-52957
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	net/ceph/osdmap.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/d55ffad8d422b5d1cc44dad32bd3d25f4471cd9f
	https://git.kernel.org/stable/c/301286c0ccd37d66b0e40786fd35a4f19cdbd88a
	https://git.kernel.org/stable/c/7169f326a23d0f547fcd90e68b72fd387622e126
	https://git.kernel.org/stable/c/d7a65a34d2453f8cd3e0cc0e1319740af7e24276
	https://git.kernel.org/stable/c/312ec973efac0efb9b9ed64214235910e9ecbaa8
	https://git.kernel.org/stable/c/f2f95e6d4b97e70bb876139b0583fc8079983f85
	https://git.kernel.org/stable/c/a20e16ebfe2fa65348eb4b2dc7deac330ce03e9c
	https://git.kernel.org/stable/c/28b0a2ab8c82d0bbdeb8013029c67c978ce6e4bf

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-06-24 16:33 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-24 16:29 CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.