CVE-2025-71116

In the Linux kernel, the following vulnerability has been resolved: libceph: make decode_pool() more resilient against corrupted osdmaps If the osdmap is (maliciously) corrupted such that the encoded length of ceph_pg_pool envelope is less than what is expected for a particular encoding version, out-of-bounds reads may ensue because the only bounds check that is there is based on that length value. This patch adds explicit bounds checks for each field that is decoded or skipped.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.9:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*

History

17 Jun 2026, 10:03

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: libceph: hacer decode_pool() más resistente contra osdmaps corruptos Si el osdmap está (maliciosamente) corrupto de tal manera que la longitud codificada del envoltorio ceph_pg_pool es menor de lo que se espera para una versión de codificación particular, pueden producirse lecturas fuera de límites porque la única comprobación de límites que existe se basa en ese valor de longitud. Este parche añade comprobaciones de límites explícitas para cada campo que se decodifica o se omite.

25 Mar 2026, 18:59

Type Values Removed Values Added
First Time Linux
Linux linux Kernel
References () https://git.kernel.org/stable/c/145d140abda80e33331c5781d6603014fa75d258 - () https://git.kernel.org/stable/c/145d140abda80e33331c5781d6603014fa75d258 - Patch
References () https://git.kernel.org/stable/c/2acb8517429ab42146c6c0ac1daed1f03d2fd125 - () https://git.kernel.org/stable/c/2acb8517429ab42146c6c0ac1daed1f03d2fd125 - Patch
References () https://git.kernel.org/stable/c/5d0d8c292531fe356c4e94dcfdf7d7212aca9957 - () https://git.kernel.org/stable/c/5d0d8c292531fe356c4e94dcfdf7d7212aca9957 - Patch
References () https://git.kernel.org/stable/c/8c738512714e8c0aa18f8a10c072d5b01c83db39 - () https://git.kernel.org/stable/c/8c738512714e8c0aa18f8a10c072d5b01c83db39 - Patch
References () https://git.kernel.org/stable/c/c82e39ff67353a5a6cbc07b786b8690bd2c45aaa - () https://git.kernel.org/stable/c/c82e39ff67353a5a6cbc07b786b8690bd2c45aaa - Patch
References () https://git.kernel.org/stable/c/d061be4c8040ffb1110d537654a038b8b6ad39d2 - () https://git.kernel.org/stable/c/d061be4c8040ffb1110d537654a038b8b6ad39d2 - Patch
References () https://git.kernel.org/stable/c/e927ab132b87ba3f076705fc2684d94b24201ed1 - () https://git.kernel.org/stable/c/e927ab132b87ba3f076705fc2684d94b24201ed1 - Patch
CWE CWE-125
CPE cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.9:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1

19 Jan 2026, 13:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/145d140abda80e33331c5781d6603014fa75d258 -
  • () https://git.kernel.org/stable/c/d061be4c8040ffb1110d537654a038b8b6ad39d2 -

14 Jan 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-14 15:16

Updated : 2026-06-17 10:03


NVD link : CVE-2025-71116

Mitre link : CVE-2025-71116

CVE.ORG link : CVE-2025-71116


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-125

Out-of-bounds Read