Impact
The vulnerability in the Linux kernel’s libceph OSD client allows a malicious reply to cause a buffer cursor to advance beyond the original read request boundary. This causes a BUG_ON assertion in ceph_msg_data_next(), leading to a kernel crash. The flaw is a classic out‑of‑bounds read, classified as CWE‑125, and results solely in a denial‑of‑service, not remote code execution.
Affected Systems
Any Linux distribution whose kernel includes the unpatched libceph path is potentially affected. The available CPE indicates the general Linux kernel, and the advis risk applies until the update that includes the extent‑map validation is installed.
Risk and Exploitability
The CVSS score of 7.5 reflects a high impact. The EPSS score is below 1 %, and the vulnerability is not yet listed in CISA’s KEV catalog, suggesting no widespread exploitation has been recorded. However, exploitation requires a compromised or malicious authenticated Ceph reply, a scenario that could occur in a mis‑configured Ceph cluster or when trust boundaries are breached.
OpenCVE Enrichment
Debian DSA