NULL pointer dereference in Linux kernel - CVE-2026-46024
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in ceph_handle_auth_reply() when handling a crafted CEPH_MSG_AUTH_REPLY message. A remote attacker can send a specially crafted auth reply message to cause a denial of service.
The issue is triggered when both the protocol and result fields in the message are zero.
How to mitigate CVE-2026-46024
Sources
- https://git.kernel.org/stable/c/016bc663657366d386993f63eb31072eb45a2b77
- https://git.kernel.org/stable/c/4b2738b93edad661178340239de657d876b73d3d
- https://git.kernel.org/stable/c/5199c125d25aeae8615c4fc31652cc0fe624338e
- https://git.kernel.org/stable/c/8f2be7285941a33a9f72579a23b96392f83c758e
- https://git.kernel.org/stable/c/927e4bd5692f2a4901808822981fb2c8d4456548