PT-2026-94415 · Linux · Linux Kernel
CVE-2026-90067
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the libceph component when parsing the Ceph messenger v2 protocol banner. The
payload len field is decoded from the banner prefix; if a client provides a payload len of 0, the kernel initiates a 0-length socket read. This action violates a state machine invariant and triggers a warning in the populate in iter() function. According to the msgr2 protocol specification, the banner payload must be at least 16 bytes to accommodate two 64-bit integers, server feat and server req feat.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel