CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-52955

Critical · CVSS 9.8

Linux Kernel (libceph) — Out-of-bounds memory access in CRUSH map decoding (CWE-131 incorrect buffer size calculation)

CVSS
9.8
nvd
EPSS
0.38%
30th pct
KEV
No
Class
oss containerizable
CWE-125, CWE-131

Description

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crush_decode() A message of type CEPH_MSG_OSD_MAP containing a crush map with at least one bucket has two fields holding the bucket algorithm. If the values in these two fields differ, an out-of-bounds access can occur. This is the case because the first algorithm field (alg) is used to allocate the correct amount of memory for a bucket of this type, while the second algorithm field inside the bucket (b->alg) is used in the subsequent processing. This patch fixes the issue by adding a check that compares alg and b->alg and aborts the processing in case they differ. Furthermore, b->alg is set to 0 in this case, because the destruction of the crush map also uses this field to determine the bucket type, which can again result in an out-of-bounds access when trying to free the memory pointed to by the fields of the bucket. To correctly free the memory allocated for the bucket in such a case, the corresponding call to kfree is moved from the algorithm-specific crush_destroy_bucket functions to the generic crush_destroy_bucket().

Search profile — drives PoC discovery

Symbols crush_decodecrush_destroy_bucketCEPH_MSG_OSD_MAPb->algalgcrush_destroy_bucket_uniformcrush_destroy_bucket_listcrush_destroy_bucket_treecrush_destroy_bucket_strawcrush_destroy_bucket_straw2kfreecrush_map
Keywords CVE-2026-52955libcephcrush_decodeout-of-boundsCRUSH mapbucket algorithmCEPH_MSG_OSD_MAPcrush_destroy_bucketLinux kernelosd mapceph crush bucket
Versions: Linux kernel versions prior to fixes at commits 0f3604cbe4df, 3f42508191e1, 4c79fc2d5986, 6e70ef53e818, cceb10023e76

Affected packages

Linux Kernel 2.6.34 → 5.10.258
Linux Kernel 5.11.0 → 5.15.209
Linux Kernel 5.16.0 → 6.1.175
Linux Kernel 6.13.0 → 6.18.33
Linux Kernel 6.19.0 → 7.0.10
Linux Kernel 6.2.0 → 6.6.141
Linux Kernel 6.7.0 → 6.12.91

References

Status: enriched · ingested 2026-07-11T00:00:26.000Z · profiled 2026-07-11T00:30:26.000Z