PT-2026-94415 · Linux · Linux Kernel

CVE-2026-90067

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the libceph component when parsing the Ceph messenger v2 protocol banner. The payload len field is decoded from the banner prefix; if a client provides a payload len of 0, the kernel initiates a 0-length socket read. This action violates a state machine invariant and triggers a warning in the populate in iter() function. According to the msgr2 protocol specification, the banner payload must be at least 16 bytes to accommodate two 64-bit integers, server feat and server req feat.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102594
CVE-2026-90067
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel