Impact
A malformed CRUSH map in the Linux kernel causes the bucket decoder to store bucket data in a bucket's workspace buffer based on an encoded bucket id that does not match its array slot. The later reuse of that workspace by the mapper results in a 4‑byte out‑of‑bounds write within the kernel’s kvmalloc‑allocated CRUSH structures, leading to kernel memory corruption.
Affected Systems
The vulnerability affects the Linux kernel, specifically any distribution or build that includes the libceph subsystem and has not yet applied the fixes contained in the referenced commits. No precise version range is listed, so all current kernels incorporating libceph remain potentially exposed until the patch is deployed.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating a critical severity level. The EPSS score is less than 1 %, suggesting a low current likelihood of exploitation, and it is not listed in the CISA KEV catalog. The attack vector likely requires an attacker to supply a malformed CRUSH map to a Ceph cluster, such as by modifying cluster configuration or a Ceph client with map editing permissions. The out‑of‑bounds write in bucket_perm_choose() can corrupt kernel memory, which could lead to a crash or, if an attacker can supply executable code, potentially arbitrary execution with kernel privileges. These consequences are inferred from typical kernel memory corruption outcomes.
OpenCVE Enrichment
Debian DSA