CVE-2026-52957
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
24/06/2026
Last modified:
14/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
libceph: Fix potential null-ptr-deref in decode_choose_args()<br />
<br />
A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself<br />
contains a CRUSH map. When decoding this CRUSH map in crush_decode(), an<br />
array of max_buckets CRUSH buckets is decoded, where some indices may<br />
not refer to actual buckets and are therefore set to NULL. The received<br />
CRUSH map may optionally contain choose_args that get decoded in<br />
decode_choose_args(). When decoding a crush_choose_arg_map, a series of<br />
choose_args for different buckets is decoded, with the bucket_index<br />
being read from the incoming message. It is only checked that the bucket<br />
index does not exceed max_buckets, but not that it doesn&#39;t point to an<br />
index with a NULL bucket. If a (potentially corrupted) message contains<br />
a crush_choose_arg_map including such a bucket_index, a null pointer<br />
dereference may occur in the subsequent processing when attempting to<br />
access the bucket with the given index.<br />
<br />
This patch fixes the issue by extending the affected check. Now, it is<br />
only attempted to access the bucket if it is not NULL.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.13.1 (including) | 5.10.258 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.209 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.175 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.141 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.91 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.33 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.10 (excluding) |
| cpe:2.3:o:linux:linux_kernel:4.13:-:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.13:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.13:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.13:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.13:rc7:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/28b0a2ab8c82d0bbdeb8013029c67c978ce6e4bf
- https://git.kernel.org/stable/c/301286c0ccd37d66b0e40786fd35a4f19cdbd88a
- https://git.kernel.org/stable/c/312ec973efac0efb9b9ed64214235910e9ecbaa8
- https://git.kernel.org/stable/c/7169f326a23d0f547fcd90e68b72fd387622e126
- https://git.kernel.org/stable/c/a20e16ebfe2fa65348eb4b2dc7deac330ce03e9c
- https://git.kernel.org/stable/c/d55ffad8d422b5d1cc44dad32bd3d25f4471cd9f
- https://git.kernel.org/stable/c/d7a65a34d2453f8cd3e0cc0e1319740af7e24276
- https://git.kernel.org/stable/c/f2f95e6d4b97e70bb876139b0583fc8079983f85



