Vulnerability in Linux Kernel Affects Multiple Ceph Deployments
CVE-2026-68082

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
8 August 2026

What is CVE-2026-68082?

A security vulnerability in the Linux kernel's libceph component could allow a malicious or compromised Object Storage Device (OSD) to exploit unsafe decode operations in the decode_lockers() function. This flaw results in out-of-bounds reads, which may allow attackers to manipulate memory and potentially execute arbitrary code. The preprocessing of structured data lacks sufficient bounds checks, leading to exploitation scenarios in multi-tenant Ceph environments. Affected systems should implement the recommended updates to mitigate the risk associated with these unsafe decode operations.

Affected Version(s)

Linux d4ed4a530562881cc5225050e42d96034f405aae

Linux d4ed4a530562881cc5225050e42d96034f405aae

Linux 4.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.