Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-52954

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/06/2026
Última modificación:
14/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> libceph: handle rbtree insertion error in decode_choose_args()<br /> <br /> A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself<br /> contains a CRUSH map. The received CRUSH map may optionally contain<br /> choose_args that get decoded in decode_choose_args(). In this function,<br /> num_choose_arg_maps is read from the message, and a corresponding number<br /> of crush_choose_arg_maps gets decoded afterwards. Each<br /> crush_choose_arg_map has a choose_args_index, which serves as the key<br /> when inserting it into the choose_args rbtree of the decoded crush_map.<br /> If a (potentially corrupted) message contains two crush_choose_arg_maps<br /> with the same index, the assertion in insert_choose_arg_map() triggers a<br /> kernel BUG when trying to insert the second crush_choose_arg_map.<br /> <br /> This patch fixes the issue by switching to the non-asserting rbtree<br /> insertion function and rejecting the message if the insertion fails.<br /> <br /> [ idryomov: changelog ]

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.13 (incluyendo) 5.10.258 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (incluyendo) 5.15.209 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (incluyendo) 6.1.175 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (incluyendo) 6.6.141 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (incluyendo) 6.12.91 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.33 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 7.0.10 (excluyendo)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*