CVE-2026-80558

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/08/2026
Last modified:
26/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> libceph: Avoid using invalid osd indices from primary_temp<br /> <br /> A corrupted osdmap received from a Ceph monitor or OSD may contain osd<br /> indices in its pg_temp, primary_temp, pg_upmap, and pg_upmap_items parts<br /> that don&amp;#39;t exist, i.e., that are greater than max_osd or smaller than<br /> CEPH_HOMELESS_OSD (-1). These indices are used to create the up and<br /> acting set in ceph_pg_to_up_acting_osds(), called from calc_target().<br /> While most of these osd indices are checked, the one from primary_temp<br /> is not. Subsequently, this may lead to calc_target() returning this<br /> (potentially invalid) index as target osd for a (linger) request.<br /> Because the osd_state, osd_weight, and osd_addr arrays only contain<br /> max_osd entries (with indices 0 to max_osd -1), this leads to<br /> out-of-bounds accesses when trying to read values from these arrays.<br /> <br /> This patch fixes the issue by adding a check to get_temp_osds(), so that<br /> only valid osd indices from primary_temp are used, and it falls back to<br /> using the primary from pg_temp or the up set if it is invalid.<br /> <br /> [ idryomov: changelog ]

Impact