Vulnerability in Linux Kernel Affecting Ceph Lock Clients
CVE-2026-80561

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-80561?

A series of unsafe decode operations in the Linux kernel's Ceph implementation can lead to severe vulnerabilities in multi-tenant environments. Specifically, the unsafe use of pointers and bounds checks in the decode_locker() function allows a compromised object storage daemon (OSD) to exploit the system by creating conditions for slab-out-of-bounds reads. An attacker can manipulate data sent from the OSD, potentially leading to unauthorized access or system crashes. Mitigations include replacing unsafe functions with secure alternatives to ensure proper bounds checking and prevent exploitation.

Affected Version(s)

Linux d4ed4a530562881cc5225050e42d96034f405aae < 1ed45c8d96498725eb54f740172f9068d8673906

Linux d4ed4a530562881cc5225050e42d96034f405aae < 6265103e78f0ee7e2518de9cf938b94bee9700a0

Linux d4ed4a530562881cc5225050e42d96034f405aae < 3c3716dc06a34e4ca7f743f5fcfa07fbc5a11070

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.