From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 034A030EF89 for ; Wed, 24 Jun 2026 16:33:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782318790; cv=none; b=kraeup9U8AJDOdkfX8kQGchBmBDQ4Wp+9NpQ2HyMq5SyJ7L1yhRrujZQ3v3JMTcfg9szCNuCPy0LFUnTwKXZA56be0+7Odcc4Eij83tp+BaVkxNGGoRdsLGaTyjdK022t9XMXaFAquOkmrmvjymAXcoJEOlAJewPxLK5GoAFMfM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782318790; c=relaxed/simple; bh=jg4GDAQxQh70Ep/KEu8PA6S5K80LYwVsT/eKuVPNdgk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=IxTUSNRV6aDfqMIINcFuecR0cZGfVg2G/cHfwS70i4Lsn40Ch/nrK8I6ihebRG22v+BJpYlzOtq2pafEX2beVWN98F6SeWcT3Qqi/pEdeHGCDexcl2OLyI3DxLN4JD4QvG8BZ1HHW6cH4bw5hrx5VAZpIRhUmSLenbg6tHrV3OQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=LzpGARXM; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="LzpGARXM" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 40B701F000E9; Wed, 24 Jun 2026 16:33:08 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1782318788; bh=fwm1NB7qlqruJkgtIkABmrlrcRaoOQ8exBXZE12sbHw=; h=From:To:Cc:Subject:Date:Reply-To; b=LzpGARXMGPuryPAVxhMKvrBQwLi+NppLZMbvbwvXv1vrhbFbgIlZaww//+uehOwrY NHhVu+N6hkxf90XbRVzqZLvCB2r0V1BVgCb47pdQH1sFIjMSTyh8fhgTo3fHGneY5G uv/czyn/oHnUH5pSAPqF2AaUb4MQvY+07/mAEChU= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() Date: Wed, 24 Jun 2026 17:29:41 +0100 Message-ID: <2026062435-CVE-2026-52957-0154@gregkh> X-Mailer: git-send-email 2.54.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3504; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=X4g1HM3XSiHKaxh8uqBM1HuL5XEeFdMuVo08cdeCDyY=; b=owGbwMvMwCRo6H6F97bub03G02pJDFk2rO/1jlx7dI49MDrx04Pgjb0ZykYTbq0/wfI6OvJE2 c8I7mmVHbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAjCR1gqGeRb5vYd/xsVNt9ia 1t4je9W06sCUTQzzXW9e/cGlx/Tw6GHh+DJ1eTWZQytdAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential null-ptr-deref in decode_choose_args() A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself contains a CRUSH map. When decoding this CRUSH map in crush_decode(), an array of max_buckets CRUSH buckets is decoded, where some indices may not refer to actual buckets and are therefore set to NULL. The received CRUSH map may optionally contain choose_args that get decoded in decode_choose_args(). When decoding a crush_choose_arg_map, a series of choose_args for different buckets is decoded, with the bucket_index being read from the incoming message. It is only checked that the bucket index does not exceed max_buckets, but not that it doesn't point to an index with a NULL bucket. If a (potentially corrupted) message contains a crush_choose_arg_map including such a bucket_index, a null pointer dereference may occur in the subsequent processing when attempting to access the bucket with the given index. This patch fixes the issue by extending the affected check. Now, it is only attempted to access the bucket if it is not NULL. The Linux kernel CVE team has assigned CVE-2026-52957 to this issue. Affected and fixed versions =========================== Fixed in 5.10.258 with commit d55ffad8d422b5d1cc44dad32bd3d25f4471cd9f Fixed in 5.15.209 with commit 301286c0ccd37d66b0e40786fd35a4f19cdbd88a Fixed in 6.1.175 with commit 7169f326a23d0f547fcd90e68b72fd387622e126 Fixed in 6.6.141 with commit d7a65a34d2453f8cd3e0cc0e1319740af7e24276 Fixed in 6.12.91 with commit 312ec973efac0efb9b9ed64214235910e9ecbaa8 Fixed in 6.18.33 with commit f2f95e6d4b97e70bb876139b0583fc8079983f85 Fixed in 7.0.10 with commit a20e16ebfe2fa65348eb4b2dc7deac330ce03e9c Fixed in 7.1 with commit 28b0a2ab8c82d0bbdeb8013029c67c978ce6e4bf Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-52957 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/ceph/osdmap.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/d55ffad8d422b5d1cc44dad32bd3d25f4471cd9f https://git.kernel.org/stable/c/301286c0ccd37d66b0e40786fd35a4f19cdbd88a https://git.kernel.org/stable/c/7169f326a23d0f547fcd90e68b72fd387622e126 https://git.kernel.org/stable/c/d7a65a34d2453f8cd3e0cc0e1319740af7e24276 https://git.kernel.org/stable/c/312ec973efac0efb9b9ed64214235910e9ecbaa8 https://git.kernel.org/stable/c/f2f95e6d4b97e70bb876139b0583fc8079983f85 https://git.kernel.org/stable/c/a20e16ebfe2fa65348eb4b2dc7deac330ce03e9c https://git.kernel.org/stable/c/28b0a2ab8c82d0bbdeb8013029c67c978ce6e4bf