PT-2026-51849 · Linux+2 · Linux Kernel+2
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw in the
libceph component allows a remote attacker to cause a system crash and a Denial of Service (DoS) by sending a specially crafted CEPH MSG OSD MAP message. The issue occurs in the crush decode() function when two internal fields, alg and b->alg, contain differing bucket algorithm values. Because alg is used for memory allocation while b->alg is used for subsequent processing and memory deallocation, this discrepancy leads to an out-of-bounds memory access.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu