In the Linux kernel, the following vulnerability has been resolved:
libceph: Fix potential out-of-bounds access in crush_decode()
A message of type CEPH_MSG_OSD_MAP containing a crush map with at least
one bucket has two fields holding the bucket algorithm. If the values
in these two fields differ, an out-of-bounds access can occur. This is
the case because the first algorithm field (alg) is used to allocate
the correct amount of memory for a bucket of this type, while the second
algorithm field inside the bucket (b->alg) is used in the subsequent
processing.
This patch fixes the issue by adding a check that compares alg and
b->alg and aborts the processing in case they differ. Furthermore,
b->alg is set to 0 in this case, because the destruction of the crush
map also uses this field to determine the bucket type, which can again
result in an out-of-bounds access when trying to free the memory pointed
to by the fields of the bucket. To correctly free the memory allocated
for the bucket in such a case, the corresponding call to kfree is moved
from the algorithm-specific crush_destroy_bucket functions to the
generic crush_destroy_bucket().
References
Configurations
Configuration 1 (hide)
|
History
14 Jul 2026, 16:43
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://git.kernel.org/stable/c/0f3604cbe4df14c5e58288ac9f57511e726a222d - Patch | |
| References | () https://git.kernel.org/stable/c/3f42508191e129ee6b5ea96578d5cab14f2a013a - Patch | |
| References | () https://git.kernel.org/stable/c/4c79fc2d598694bda845b46229c9d48b65042970 - Patch | |
| References | () https://git.kernel.org/stable/c/6e70ef53e818c53eab28d7b0026b7fd03dddaba5 - Patch | |
| References | () https://git.kernel.org/stable/c/cceb10023e76bc89f3fe9238ebd0ccab0fc7c7c5 - Patch | |
| References | () https://git.kernel.org/stable/c/ea0d42137f0c06da71e37ffc647aab4c5309599a - Patch | |
| References | () https://git.kernel.org/stable/c/ebe76d58a48a48031b98543d86c4cd30a825b622 - Patch | |
| References | () https://git.kernel.org/stable/c/fb176a99e4c1a5a8448a83d83d3606203ba81faa - Patch | |
| References | () https://access.redhat.com/security/cve/CVE-2026-52955 - Third Party Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2492328 - Third Party Advisory | |
| References | () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52955.json - Third Party Advisory | |
| First Time |
Linux linux Kernel
Linux |
|
| CWE | CWE-125 | |
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.34:rc7:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.34:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.34:-:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.34:rc5:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.34:rc6:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.34:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:2.6.34:rc4:*:*:*:*:*:* |
30 Jun 2026, 03:20
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CWE | CWE-131 |
28 Jun 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
24 Jun 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-24 17:17
Updated : 2026-07-15 01:16
NVD link : CVE-2026-52955
Mitre link : CVE-2026-52955
CVE.ORG link : CVE-2026-52955
JSON object : View
Products Affected
linux
- linux_kernel
