PT-2026-82177 · Linux+1 · Linux Kernel+1

CVE-2026-80561

·

Published

2026-08-26

·

Updated

2026-08-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description In the Linux kernel, the decode locker() function within cls lock client.c contains three unsafe decode operations. A malicious or compromised OSD (Object Storage Device) in a multi-tenant Ceph deployment can exploit these to trigger slab-out-of-bounds reads against any kernel client that issues the lock.get info class method, such as during RBD exclusive lock acquisition. The issues involve a missing bounds check in ceph decode copy() for the locker id t name field, an unchecked pointer advance after the locker info t header, and a missing bounds check in ceph decode 32(p) followed by an uncapped pointer advance. Slab-out-of-bounds reads occur when a program reads data past the end of a memory chunk allocated from a slab allocator, potentially exposing sensitive information or causing system instability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-97784
CVE-2026-80561

Affected Products

Ceph
Linux Kernel