{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-68160","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-30T09:28:09.371Z","datePublished":"2026-08-10T11:59:26.741Z","dateUpdated":"2026-08-19T16:30:32.455Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-19T16:30:32.455Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()\n\nceph_handle_caps() reads snap_trace_len from the wire-format\nceph_mds_caps header and uses it unconditionally to build a fake\nend pointer (snaptrace + snaptrace_len) that is later handed to\nceph_update_snap_trace() in the CEPH_CAP_OP_IMPORT case:\n\n    snaptrace     = h + 1;\n    snaptrace_len = le32_to_cpu(h->snap_trace_len);\n    p             = snaptrace + snaptrace_len;\n    ...\n    case CEPH_CAP_OP_IMPORT:\n        if (snaptrace_len) {\n            ...\n            if (ceph_update_snap_trace(mdsc, snaptrace,\n                                       snaptrace + snaptrace_len,\n                                       false, &realm)) { ... }\n\nceph_update_snap_trace() then decodes a struct ceph_mds_snap_realm\nfrom snaptrace using ceph_decode_need(&p, e, sizeof(*ri), bad)\nwith the attacker-supplied fake end e == snaptrace + snaptrace_len.\nWith snaptrace_len == 0xFFFFFFFF the bound check is trivially\nsatisfied, ri = p reads sizeof(struct ceph_mds_snap_realm) past\nthe legitimate msg->front buffer, and ri->num_snaps /\nri->num_prior_parent_snaps then drive further out-of-bounds\nreads of the encoded snap arrays.\n\nThe eleven msg_version >= 2 .. msg_version >= 12 decoder blocks\nabove the op switch each catch this OOB through their\nceph_decode_*_safe() / ceph_decode_need() helpers, but they sit\nbehind a hdr.version-gated if, so a malicious or compromised\nMDS that sets msg->hdr.version = 1 reaches the IMPORT path with\nno version-gated decoder having validated snap_trace_len. The\nshape has been present since ceph_handle_caps() was introduced.\n\nValidate snap_trace_len against the message front buffer before\nconsuming it, using the canonical ceph_decode_need() / ceph_has_room()\nhelper.  The helper bounds the length with subtraction (n <= end - p,\nguarded by end >= p) rather than pointer addition, so it is wrap-safe\nfor the attacker-controlled u32 length on 32-bit builds where\np + snap_trace_len could overflow the address space.  This matches the\nrest of the ceph decode path (e.g. the pool_ns_len check a few lines\nbelow), and the existing goto bad cleanup already covers this exit\npath."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - CEPH_MSG_CLIENT_CAPS is received over the kernel Ceph messenger TCP connection from an MDS peer; mds_dispatch() passes it directly to ceph_handle_caps(), so a malicious or compromised MDS (or on-path attacker on an unsigned msgr session) reaches the bug with network data alone.\nAC:L - The attacker fully controls msg->hdr.version and snap_trace_len in the caps header; setting version=1 bypasses all version-gated decoders and snap_trace_len=0xFFFFFFFF yields a fake end pointer that reliably defeats ceph_decode_need(), with no race or memory-layout dependency.\nPR:N - Exploitation requires only the ability to send crafted caps messages as the remote MDS peer on an established session; the attacker needs no account, mount privilege, or other credentials on the victim host beyond the client already being connected to that cluster.\nUI:N - Once CephFS is mounted and the MDS session is open, CEPH_CAP_OP_IMPORT caps messages are delivered and processed automatically during normal cap migration and MDS failover; no additional local user action is needed at exploit time beyond prior cluster connectivity.\nS:U - The out-of-bounds read and resulting snap-realm corruption affect only the kernel CephFS client’s internal state within the same kernel security authority; there is no VM escape, sandbox breakout, or cross-authority boundary crossing.\nC:H - ceph_update_snap_trace() decodes struct ceph_mds_snap_realm and snap arrays using an attacker-supplied fake end pointer, reading sizeof(*ri) and further attacker-influenced extents past the legitimate msg->front buffer into adjacent kernel memory without copying to userspace.\nI:H - Out-of-bounds kernel memory is interpreted as snap-realm metadata and copied via dup_array() into newly allocated kernel heap structures (realm->snaps, realm->prior_parent_snaps), corrupting authoritative snap state and providing a memory-corruption primitive that could be leveraged for further kernel compromise.\nA:H - Out-of-bounds reads can fault on unmapped pages causing a kernel oops; the ceph_update_snap_trace() error path issues WARN(1), fences I/O via CEPH_MOUNT_FENCE_IO, and can close all MDS sessions—effects an attacker can trigger repeatedly at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ceph/caps.c"],"versions":[{"version":"a8599bd821d084d04a3290fffae1071624ec00ea","lessThan":"f913192fc782288e060dafc329b2346934be34cc","status":"affected","versionType":"git"},{"version":"a8599bd821d084d04a3290fffae1071624ec00ea","lessThan":"0c011137194036424e974677e0f1592e22a33d8c","status":"affected","versionType":"git"},{"version":"a8599bd821d084d04a3290fffae1071624ec00ea","lessThan":"cc93f68a31c9b831abf2db8647b5f5b10329d793","status":"affected","versionType":"git"},{"version":"a8599bd821d084d04a3290fffae1071624ec00ea","lessThan":"9081c71796724ffe96cba253f68fbe42363c5295","status":"affected","versionType":"git"},{"version":"a8599bd821d084d04a3290fffae1071624ec00ea","lessThan":"03b417afce19ee6b6e61f1bbbbebac924c9f36d1","status":"affected","versionType":"git"},{"version":"a8599bd821d084d04a3290fffae1071624ec00ea","lessThan":"a4228b93706fb74a484e6ffb271c1cc2af3a2ddb","status":"affected","versionType":"git"},{"version":"a8599bd821d084d04a3290fffae1071624ec00ea","lessThan":"71893c342a26bcff92eaab0b2b75d64aed19308a","status":"affected","versionType":"git"},{"version":"a8599bd821d084d04a3290fffae1071624ec00ea","lessThan":"4dbc71bcaf9a30abf3920a4e2cc4ed33bba78c02","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ceph/caps.c"],"versions":[{"version":"2.6.34","status":"affected"},{"version":"0","lessThan":"2.6.34","status":"unaffected","versionType":"semver"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34","versionEndExcluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34","versionEndExcluding":"6.6.148"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34","versionEndExcluding":"6.12.101"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34","versionEndExcluding":"6.18.42"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34","versionEndExcluding":"7.1.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.34","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f913192fc782288e060dafc329b2346934be34cc"},{"url":"https://git.kernel.org/stable/c/0c011137194036424e974677e0f1592e22a33d8c"},{"url":"https://git.kernel.org/stable/c/cc93f68a31c9b831abf2db8647b5f5b10329d793"},{"url":"https://git.kernel.org/stable/c/9081c71796724ffe96cba253f68fbe42363c5295"},{"url":"https://git.kernel.org/stable/c/03b417afce19ee6b6e61f1bbbbebac924c9f36d1"},{"url":"https://git.kernel.org/stable/c/a4228b93706fb74a484e6ffb271c1cc2af3a2ddb"},{"url":"https://git.kernel.org/stable/c/71893c342a26bcff92eaab0b2b75d64aed19308a"},{"url":"https://git.kernel.org/stable/c/4dbc71bcaf9a30abf3920a4e2cc4ed33bba78c02"}],"title":"ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()","x_generator":{"engine":"bippy-1.2.0"}}}}