Vulnerability in Linux Kernel Affects Multiple Ceph Deployments
CVE-2026-68082
Currently unrated
What is CVE-2026-68082?
A security vulnerability in the Linux kernel's libceph component could allow a malicious or compromised Object Storage Device (OSD) to exploit unsafe decode operations in the decode_lockers() function. This flaw results in out-of-bounds reads, which may allow attackers to manipulate memory and potentially execute arbitrary code. The preprocessing of structured data lacks sufficient bounds checks, leading to exploitation scenarios in multi-tenant Ceph environments. Affected systems should implement the recommended updates to mitigate the risk associated with these unsafe decode operations.
Affected Version(s)
Linux d4ed4a530562881cc5225050e42d96034f405aae
Linux d4ed4a530562881cc5225050e42d96034f405aae
Linux 4.9