{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-52958","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-06-09T07:44:35.373Z","datePublished":"2026-06-24T16:28:39.723Z","dateUpdated":"2026-08-05T12:32:08.518Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:32:08.518Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Fix potential out-of-bounds access in osdmap_decode()\n\nWhen decoding osd_state and osd_weight from an incoming osdmap in\nosdmap_decode(), both are decoded for each osd, i.e., map->max_osd\ntimes. The ceph_decode_need() check only accounts for\nsizeof(*map->osd_weight) once. This can potentially result in an\nout-of-bounds memory access if the incoming message is corrupted such\nthat the max_osd value exceeds the actual content of the osdmap message.\n\nThis patch fixes the issue by changing the corresponding part in the\nceph_decode_need() check to account for\nmap->max_osd*sizeof(*map->osd_weight)."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":9.1,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The vulnerable decoder processes Ceph OSD map messages received over Ceph messenger connections from monitors or OSDs. A malicious or compromised network Ceph peer can deliver the crafted map to a connected kernel client.\nAC:L - The trigger is a deterministic malformed OSD map with `max_osd` larger than the supplied `osd_weight` content. No race or condition outside the attacker's control is required.\nPR:N - The attacker does not need privileges on the vulnerable Linux system; the crafted data is supplied by a remote Ceph peer. Ceph also supports auth-none deployments, so the highest defensible scenario does not require authenticated attacker privileges.\nUI:N - Once the kernel Ceph client is connected, OSD map updates are processed asynchronously without a user action. The attacker can trigger parsing by sending the crafted map over the established network connection.\nS:U - The impact is within the kernel/client system that parses the malicious Ceph message. This is not a VM escape, IOMMU bypass, or other cross-scope boundary change.\nC:H - The bug is an out-of-bounds read from the received message buffer, and the read can extend beyond a small bounded area based on attacker-controlled `max_osd`. Following the higher-severity rule for OOB reads, this supports high confidentiality impact.\nI:N - The faulty loop reads past the input buffer into the allocated `osd_weight` array but does not write out of bounds or provide a clear kernel memory write primitive. The malformed full map is rejected after decoding fails.\nA:H - The out-of-bounds kernel read can fault or otherwise crash the kernel when it crosses invalid memory, and malformed OSD maps can be sent repeatedly by the network peer. Kernel crash or oops is high availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/ceph/osdmap.c"],"versions":[{"version":"dcbc919a5dc8c2629684a113a90c0b6fe10c3462","lessThan":"36a79759a288961b1ff28a68ec2d1f56f6848098","status":"affected","versionType":"git"},{"version":"dcbc919a5dc8c2629684a113a90c0b6fe10c3462","lessThan":"3f2575bb7f955d42569d96c3e04fa958a0dcf4b4","status":"affected","versionType":"git"},{"version":"dcbc919a5dc8c2629684a113a90c0b6fe10c3462","lessThan":"8713bbc4b2b9ad78f803978e54b7e49dd21bd9be","status":"affected","versionType":"git"},{"version":"dcbc919a5dc8c2629684a113a90c0b6fe10c3462","lessThan":"0d2dd7e6bb74fd7712aa73457a4a821906c6863a","status":"affected","versionType":"git"},{"version":"dcbc919a5dc8c2629684a113a90c0b6fe10c3462","lessThan":"e7187f33c02488697ec0d01d82bf7a3f8deaba8f","status":"affected","versionType":"git"},{"version":"dcbc919a5dc8c2629684a113a90c0b6fe10c3462","lessThan":"48df98d12b15360cd56af5c1f460307b340c1197","status":"affected","versionType":"git"},{"version":"dcbc919a5dc8c2629684a113a90c0b6fe10c3462","lessThan":"ee933694645dac062d65fc2743f92bc06fa0db6b","status":"affected","versionType":"git"},{"version":"dcbc919a5dc8c2629684a113a90c0b6fe10c3462","lessThan":"35d0ed82d03e5ee77ea4f31f20e29562a7721649","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/ceph/osdmap.c"],"versions":[{"version":"5.3","status":"affected"},{"version":"0","lessThan":"5.3","status":"unaffected","versionType":"semver"},{"version":"5.10.258","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.209","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.175","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.141","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.91","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.33","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.10","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"5.10.258"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"5.15.209"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.1.175"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.6.141"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.12.91"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"6.18.33"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"7.0.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/36a79759a288961b1ff28a68ec2d1f56f6848098"},{"url":"https://git.kernel.org/stable/c/3f2575bb7f955d42569d96c3e04fa958a0dcf4b4"},{"url":"https://git.kernel.org/stable/c/8713bbc4b2b9ad78f803978e54b7e49dd21bd9be"},{"url":"https://git.kernel.org/stable/c/0d2dd7e6bb74fd7712aa73457a4a821906c6863a"},{"url":"https://git.kernel.org/stable/c/e7187f33c02488697ec0d01d82bf7a3f8deaba8f"},{"url":"https://git.kernel.org/stable/c/48df98d12b15360cd56af5c1f460307b340c1197"},{"url":"https://git.kernel.org/stable/c/ee933694645dac062d65fc2743f92bc06fa0db6b"},{"url":"https://git.kernel.org/stable/c/35d0ed82d03e5ee77ea4f31f20e29562a7721649"}],"title":"libceph: Fix potential out-of-bounds access in osdmap_decode()","x_generator":{"engine":"bippy-1.2.0"}}}}