PT-2026-4484 · Linux+4 · Linux Kernel+4

·

CVE-2026-22984

·

Published

2026-01-01

·

Updated

2026-08-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The libceph component in the Linux kernel contains a flaw where an out-of-bounds read could occur in the handle auth done() function. This is due to a missing bounds check on the payload len variable, potentially leading to unauthorized access. The issue is addressed by implementing an explicit bounds check on payload len before the callout is made.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:19568
ALSA-2026:25120
ALSA-2026:25121
AZL-78464
BDU:2026-09417
CVE-2026-22984
ECHO-608E-31D9-7F37
OESA-2026-1566
OESA-2026-1567
OESA-2026-1570
OPENSUSE-SU-2026:20287-1
RHSA-2026:19568
RHSA-2026:25120
RHSA-2026:25121
RHSA-2026:25218
RHSA-2026:26462
RHSA-2026:26515
RHSA-2026:26563
RHSA-2026:27735
RHSA-2026:33899
RHSA-2026:35896
SUSE-SU-2026:0447-1
SUSE-SU-2026:0472-1
SUSE-SU-2026:0587-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20555-1
SUSE-SU-2026:20570-1
SUSE-SU-2026:20599-1
SUSE-SU-2026:20615-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8116-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8243-1
USN-8278-1
USN-8278-2
USN-8289-1
USN-8289-2
USN-8296-1
USN-8296-2
USN-8393-1
USN-8440-1
USN-8490-1
USN-8490-2
USN-8491-1
USN-8499-1
USN-8508-1
USN-8545-1
USN-8546-1
USN-8604-1
USN-8605-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu
Libceph