CVE-2026-52957
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-476
Desreferencia a puntero nulo (NULL)
Fecha de publicación:
24/06/2026
Última modificación:
14/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
libceph: Fix potential null-ptr-deref in decode_choose_args()<br />
<br />
A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself<br />
contains a CRUSH map. When decoding this CRUSH map in crush_decode(), an<br />
array of max_buckets CRUSH buckets is decoded, where some indices may<br />
not refer to actual buckets and are therefore set to NULL. The received<br />
CRUSH map may optionally contain choose_args that get decoded in<br />
decode_choose_args(). When decoding a crush_choose_arg_map, a series of<br />
choose_args for different buckets is decoded, with the bucket_index<br />
being read from the incoming message. It is only checked that the bucket<br />
index does not exceed max_buckets, but not that it doesn&#39;t point to an<br />
index with a NULL bucket. If a (potentially corrupted) message contains<br />
a crush_choose_arg_map including such a bucket_index, a null pointer<br />
dereference may occur in the subsequent processing when attempting to<br />
access the bucket with the given index.<br />
<br />
This patch fixes the issue by extending the affected check. Now, it is<br />
only attempted to access the bucket if it is not NULL.
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.13.1 (incluyendo) | 5.10.258 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (incluyendo) | 5.15.209 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (incluyendo) | 6.1.175 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (incluyendo) | 6.6.141 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (incluyendo) | 6.12.91 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (incluyendo) | 6.18.33 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.10 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:4.13:-:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.13:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.13:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.13:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.13:rc7:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/28b0a2ab8c82d0bbdeb8013029c67c978ce6e4bf
- https://git.kernel.org/stable/c/301286c0ccd37d66b0e40786fd35a4f19cdbd88a
- https://git.kernel.org/stable/c/312ec973efac0efb9b9ed64214235910e9ecbaa8
- https://git.kernel.org/stable/c/7169f326a23d0f547fcd90e68b72fd387622e126
- https://git.kernel.org/stable/c/a20e16ebfe2fa65348eb4b2dc7deac330ce03e9c
- https://git.kernel.org/stable/c/d55ffad8d422b5d1cc44dad32bd3d25f4471cd9f
- https://git.kernel.org/stable/c/d7a65a34d2453f8cd3e0cc0e1319740af7e24276
- https://git.kernel.org/stable/c/f2f95e6d4b97e70bb876139b0583fc8079983f85



