CVE-2026-68157
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
10/08/2026
Última modificación:
19/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
libceph: guard missing CRUSH type name lookup<br />
<br />
Localized read selection can walk a parent bucket whose name exists in<br />
the CRUSH map while its type has no matching entry in type_names.<br />
get_immediate_parent() then dereferences a NULL type_cn and passes an<br />
invalid pointer into strcmp(), causing a null-ptr-deref.<br />
<br />
Skip such malformed parent buckets unless both the bucket name and type<br />
name metadata are present. This keeps malformed hierarchy data from<br />
crashing locality lookup and safely falls back to "not local".<br />
<br />
[ idryomov: add WARN_ON_ONCE ]
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/3767c9f0c1bbd98dd25cb088356a0fc6c1f09f50
- https://git.kernel.org/stable/c/4716a64b7cc2797741f7be4e283ace78a9dff37d
- https://git.kernel.org/stable/c/6a4b75d90f0cfbf22c14742ab35a803bc13f36ec
- https://git.kernel.org/stable/c/8ff579ac03d6e9d17d6d9c8443110167c14a382d
- https://git.kernel.org/stable/c/bbeae12fda3384a90fbebc8a19ba9d33f85b5361
- https://git.kernel.org/stable/c/c46d82c47afc968d6ee8ef4470fa2dd35b765c21
- https://git.kernel.org/stable/c/cbfcba275326c8c7dae9acd8f4a0d4c316fdafb0
- https://git.kernel.org/stable/c/db9cc9fd9660b2d69ee66f5a4cbec83c21a1c64d


