Out-of-Bounds Access Vulnerability in Linux Kernel's Ceph Storage System
CVE-2026-80558
What is CVE-2026-80558?
A vulnerability has been detected in the Linux kernel's handling of the Ceph storage system related to the use of invalid object storage device (OSD) indices. When a corrupted OSD map is received, it could contain out-of-bounds indices that exceed the maximum threshold or fall below a defined minimum, leading to potential unauthorized access to memory segments. This flaw affects the primary_temp index used in Ceph's routing functions, specifically during the selection of target OSDs for requests. Failure to validate these indices can result in memory access violations, emphasizing the need for thorough input validation to maintain system integrity.
Affected Version(s)
Linux 5e8d4d36bf23bb7baf027c479d54395840219928 < 505fc50b8ff8e687b7e3ef6866269dea27366224
Linux 5e8d4d36bf23bb7baf027c479d54395840219928 < 1c705fe8e59c6b16f48964973fb23c8ec4735b73
Linux 5e8d4d36bf23bb7baf027c479d54395840219928