Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-90067
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to trigger a kernel warning.
The vulnerability exists due to improper validation of banner payload length in the Ceph messenger v2 banner parser when parsing a crafted protocol banner. A remote attacker can send a banner with a zero-length payload to trigger a kernel warning.
The protocol requires banner payloads to contain at least two 64-bit feature fields.
Affected software
How to mitigate CVE-2026-90067
External References
- https://git.kernel.org/stable/c/279c0852999fd2384f4a88155091a99e81f96873
- https://git.kernel.org/stable/c/3b2e62a7655d347a845a91155610ddae11daffc6
- https://git.kernel.org/stable/c/6cf666e47f2b51d5a887ec8a3226cde951757d27
- https://git.kernel.org/stable/c/6d1c6f228854aa89844fd0152d7ed7ac72a55e89
- https://git.kernel.org/stable/c/c1b937ff24b19e69aa7fb1b0f46a74d4c9668692
- https://git.kernel.org/stable/c/c77633a9595658210a6e216a071e5a396a0835a7
- https://git.kernel.org/stable/c/f374967fcdf04001c9b66df1c19106fa83cd91f7