CVE-2026-52955
Description
In the Linux kernel, the following vulnerability has been resolved:
libceph: Fix potential out-of-bounds access in crush_decode()
A message of type CEPH_MSG_OSD_MAP containing a crush map with at least one bucket has two fields holding the bucket algorithm. If the values in these two fields differ, an out-of-bounds access can occur. This is the case because the first algorithm field (alg) is used to allocate the correct amount of memory for a bucket of this type, while the second algorithm field inside the bucket (b->alg) is used in the subsequent processing.
This patch fixes the issue by adding a check that compares alg and b->alg and aborts the processing in case they differ. Furthermore, b->alg is set to 0 in this case, because the destruction of the crush map also uses this field to determine the bucket type, which can again result in an out-of-bounds access when trying to free the memory pointed to by the fields of the bucket. To correctly free the memory allocated for the bucket in such a case, the corresponding call to kfree is moved from the algorithm-specific crush_destroy_bucket functions to the generic crush_destroy_bucket().
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
26cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=2.6.34.1,<5.10.258
- cpe:2.3:o:linux:linux_kernel:2.6.34:-:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.34:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.34:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.34:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.34:rc5:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.34:rc6:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.34:rc7:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
- (no CPE)
- osv-coords14 versionspkg:linux/kernelpkg:rpm/opensuse/dtb-aarch64&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-64kb&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-azure&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-default&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-default-base&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-docs&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-kvmsmall&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-obs-build&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-obs-qa&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-rt&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-source&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-syms&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/kernel-zfcpdump&distro=openSUSE%20Leap%2016.0
>= 2.6.34, < 5.10.258+ 13 more
- (no CPE)range: >= 2.6.34, < 5.10.258
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1.160000.2.17
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
- (no CPE)range: < 6.12.0-160000.36.1
Patches
Vulnerability mechanics
References
11- git.kernel.org/stable/c/0f3604cbe4df14c5e58288ac9f57511e726a222dnvdPatch
- git.kernel.org/stable/c/3f42508191e129ee6b5ea96578d5cab14f2a013anvdPatch
- git.kernel.org/stable/c/4c79fc2d598694bda845b46229c9d48b65042970nvdPatch
- git.kernel.org/stable/c/6e70ef53e818c53eab28d7b0026b7fd03dddaba5nvdPatch
- git.kernel.org/stable/c/cceb10023e76bc89f3fe9238ebd0ccab0fc7c7c5nvdPatch
- git.kernel.org/stable/c/ea0d42137f0c06da71e37ffc647aab4c5309599anvdPatch
- git.kernel.org/stable/c/ebe76d58a48a48031b98543d86c4cd30a825b622nvdPatch
- git.kernel.org/stable/c/fb176a99e4c1a5a8448a83d83d3606203ba81faanvdPatch
- access.redhat.com/security/cve/CVE-2026-52955nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdThird Party Advisory
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52955.jsonnvdThird Party Advisory
News mentions
0No linked articles in our index yet.