PT-2026-51852 · Linux+2 · Linux Kernel+2
CVE-2026-52958
·
Published
2026-05-11
·
Updated
2026-09-10
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An out-of-bounds memory access issue exists in the
osdmap decode() function within libceph. The problem occurs when decoding osd state and osd weight from an incoming osdmap, as the ceph decode need() check only accounts for the size of osd weight once instead of multiplying it by the map->max osd value. If an incoming message is corrupted and the map->max osd value exceeds the actual content of the message, it can lead to memory access outside the intended boundaries.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu