Out-of-Bounds Read Vulnerability in Ceph Client for Linux Kernel
CVE-2026-80557

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-80557?

This vulnerability exists in the Ceph client for the Linux kernel, specifically in the handling of certain responses from an Object Storage Device (OSD). It arises from a failure to implement proper bounds checking when decoding watcher responses. When a malicious or compromised OSD sends a response with struct_len=0, the client can proceed with a read operation that surpasses the acceptable limits of the buffer. This oversight can lead to unpredictable behavior and potentially allow an attacker to manipulate memory usage in a multi-tenant environment. The issue has been addressed by employing safer decoding techniques in the affected function to prevent further instances of out-of-bounds access.

Affected Version(s)

Linux a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c < 7130d94846dadbb97b6b7f4d78a3a7bba6e3daa1

Linux a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c < 00ead17c7de137a692edee59f2772e6af687e8eb

Linux 4.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.