7.5

CVE-2026-89657

libceph: validate OSD extent maps before cursor advance

In the Linux kernel, the following vulnerability has been resolved:

libceph: validate OSD extent maps before cursor advance

net/ceph/osd_client.c:osd_sparse_read() validates that the sparse-read
data length matches the summed extent lengths, but it does not validate
that each OSD-supplied extent is monotonic and lies inside the original
request range. A malformed authenticated OSD reply can advertise a
far-forward nonzero extent offset with a matching data length and make
the client advance the message-data cursor beyond the request buffer.
This reaches the BUG_ON(!*length) assertion in ceph_msg_data_next() from
the client receive path.

Impact: A malicious or compromised authenticated Ceph OSD peer can crash
a kernel Ceph client via a malformed sparse-read reply.

Reject sparse extent maps that overflow, move backwards, overlap, or
extend outside the original sparse-read request before advancing the
cursor.

[ idryomov: perform sparse_extent_map_valid() check a bit earlier,
  in CEPH_SPARSE_READ_DATA_LEN instead of CEPH_SPARSE_READ_DATA_PRE
  state ]
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f628d799972799023d32c2542bb2639eb8c4f84e
Version < 94ae5145c520618802b0a24c047dcd5f05835db8
Status affected
Version f628d799972799023d32c2542bb2639eb8c4f84e
Version < 058ffa81f9440c5b4714685611cf697fd3739ec9
Status affected
Version f628d799972799023d32c2542bb2639eb8c4f84e
Version < 2571b35883268a266554e80d368e67fdfea7fb9d
Status affected
Version f628d799972799023d32c2542bb2639eb8c4f84e
Version < 201db408872ca12cf09e36bf0f560138c3dcfa1c
Status affected
Version f628d799972799023d32c2542bb2639eb8c4f84e
Version < 9ec08b7499a62c6d4afa93d36ab47a43fcad57d1
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.6
Status affected
Version 0
Version < 6.6
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.47
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/058ffa81f9440c5b4714685611cf697fd3739ec9
https://git.kernel.org/stable/c/2571b35883268a266554e80d368e67fdfea7fb9d
https://git.kernel.org/stable/c/201db408872ca12cf09e36bf0f560138c3dcfa1c
https://git.kernel.org/stable/c/9ec08b7499a62c6d4afa93d36ab47a43fcad57d1
https://git.kernel.org/stable/c/94ae5145c520618802b0a24c047dcd5f05835db8