Impact
A missing validation in the Ceph messenger v2 banner parsing allows a client to send a banner with a payload length of zero. The kernel then performs a zero‑length socket read, violating an invariant in the state machine and emitting a warning. While the fix simply aborts the connection with a protocol error, the exposed bug represents an improper input validation flaw that could be abused to disrupt Ceph communication between nodes.
Affected Systems
The flaw resides in the Linux kernel’s Ceph messenger v2 implementation and affects all kernel versions that do not contain the commit adding the payload length check. The affected product is Linux kernel; specific versions are not listed in the available data.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is considered medium‑high severity. The EPSS score of less than 1% indicates a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network‑based: a malicious Ceph client or node that can reach the kernel’s Ceph interface can send a malformed banner. Successful exploitation would abort the connection, potentially degrading availability of the affected Ceph cluster.
OpenCVE Enrichment
Debian DLA
Debian DSA