CVE-2026-52954

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/06/2026
Last modified:
14/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> libceph: handle rbtree insertion error in decode_choose_args()<br /> <br /> A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself<br /> contains a CRUSH map. The received CRUSH map may optionally contain<br /> choose_args that get decoded in decode_choose_args(). In this function,<br /> num_choose_arg_maps is read from the message, and a corresponding number<br /> of crush_choose_arg_maps gets decoded afterwards. Each<br /> crush_choose_arg_map has a choose_args_index, which serves as the key<br /> when inserting it into the choose_args rbtree of the decoded crush_map.<br /> If a (potentially corrupted) message contains two crush_choose_arg_maps<br /> with the same index, the assertion in insert_choose_arg_map() triggers a<br /> kernel BUG when trying to insert the second crush_choose_arg_map.<br /> <br /> This patch fixes the issue by switching to the non-asserting rbtree<br /> insertion function and rejecting the message if the insertion fails.<br /> <br /> [ idryomov: changelog ]

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.13 (including) 5.10.258 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.209 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.175 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.141 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.91 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.33 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.10 (excluding)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*