Impact
An unbounded length field in libceph allows a malicious Ceph monitor to craft pg_temp or pg_upmap entries with a length that exceeds the defined maximum. When decoded, the value is later copied into a fixed‑size on‑stack array, causing a stack out‑of‑bounds write. This buffer overflow can result in a kernel crash or, if exploited carefully, arbitrary code execution with kernel privileges.
Affected Systems
All Linux kernel installations that include the Ceph kernel module are affected. Whoever runs a Linux distribution with Ceph support in the kernel—regardless of vendor or kernel release—has the potential to be impacted, because the issue is not tied to a specific vendor or version. Any system that communicates with Ceph monitors or receives OSD maps is at risk.
Risk and Exploitability
The EPSS score is < 1%, indicating a very low but nonzero exploitation probability. The CVSS score of 9.8 reflects critical severity, positioning the flaw as a high‑risk kernel vulnerability that can cause a crash or kernel privilege escalation. The vulnerability is not listed in CISA’s KEV catalog, so no publicly documented exploitation has been reported. The attack requires an attacker who can inject a malicious OSDMap—typically via a compromised or poorly isolated Ceph monitor. The unbounded length field causes a stack overflow that can trigger a kernel crash or, with careful exploitation, arbitrary code execution with kernel privileges, underscoring the need for immediate action.
OpenCVE Enrichment
Debian DSA