SB20260812387 - Improper input validation in Linux kernel ceph
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-68155)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in ceph_monmap_decode() when processing a CEPH_MSG_MON_MAP monmap message. A remote attacker can send a specially crafted monmap advertising zero monitors to cause a denial of service.
The issue is triggered when the client later attempts to open a session with a monitor, causing an assertion in pick_new_mon() to fire.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0591a15815b498be628a937146e44487d599ba33
- https://git.kernel.org/stable/c/3b249546f59c3d6d3592c10657f82bc3f1faa07c
- https://git.kernel.org/stable/c/40480eee361ed9676b3f844d532ac28b47251634
- https://git.kernel.org/stable/c/cd0d41bc569632eaaeccde9d2a6bc919ec00c407
- https://git.kernel.org/stable/c/e67e8b694872c9bc66996040f9de9242f6236ed9