7.8

CVE-2026-52962

ceph: fix a buffer leak in __ceph_setxattr()

In the Linux kernel, the following vulnerability has been resolved:

ceph: fix a buffer leak in __ceph_setxattr()

The old_blob in __ceph_setxattr() can store
ci->i_xattrs.prealloc_blob value during the retry.
However, it is never called the ceph_buffer_put()
for the old_blob object. This patch fixes the issue of
the buffer leak.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 4.4.192 < 4.5
LinuxLinux Kernel Version >= 4.9.192 < 4.10
LinuxLinux Kernel Version >= 4.14.143 < 4.15
LinuxLinux Kernel Version >= 4.19.72 < 4.20
LinuxLinux Kernel Version >= 5.2.14 < 5.3
LinuxLinux Kernel Version >= 5.3.1 < 5.10.258
LinuxLinux Kernel Version >= 5.11 < 5.15.209
LinuxLinux Kernel Version >= 5.16 < 6.1.175
LinuxLinux Kernel Version >= 6.2 < 6.6.141
LinuxLinux Kernel Version >= 6.7 < 6.12.91
LinuxLinux Kernel Version >= 6.13 < 6.18.33
LinuxLinux Kernel Version >= 6.19 < 7.0.10
LinuxLinux Kernel Version5.3 Update-
LinuxLinux Kernel Version5.3 Updaterc6
LinuxLinux Kernel Version5.3 Updaterc7
LinuxLinux Kernel Version5.3 Updaterc8
LinuxLinux Kernel Version7.1 Updaterc1
LinuxLinux Kernel Version7.1 Updaterc2
LinuxLinux Kernel Version7.1 Updaterc3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.037
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://git.kernel.org/stable/c/521e5aba857fd267624892c8dd6295f22ce0267e
Patch
https://git.kernel.org/stable/c/d0cb994605c84a159c1d00d72cdc8583c321ef95
Patch
https://git.kernel.org/stable/c/ecf94823c5c6a20790bb76ed2816822b0beb0c22
Patch
https://git.kernel.org/stable/c/4bfdcefdaa6092a06cacd59389c7756b36e6de8c
Patch
https://git.kernel.org/stable/c/7d3e8d2d648d5f0df29b4710246680f47695fe94
Patch
https://git.kernel.org/stable/c/3fa13ceefbc5f36131110342743994cb3de80637
Patch
https://git.kernel.org/stable/c/bc7abce4460e490dcb579eec770f175b150b685f
Patch
https://git.kernel.org/stable/c/5d3cc36b4e77a27ce7b686b7c59c7072bcb3fa8e
Patch