Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-46119

libceph: Fix slab-out-of-bounds access in auth message processing
Back to all
CVE

CVE-2026-46119

libceph: Fix slab-out-of-bounds access in auth message processing

In the Linux kernel, the following vulnerability has been resolved:

libceph: Fix slab-out-of-bounds access in auth message processing

If a (potentially corrupted) message of type CEPHMSGAUTH_REPLY

contains a positive value in its result field, it is treated as an

error code by cephhandleauth_reply() and returned to

handleauthreply(). Thereafter, an attempt is made to send the

preallocated message of type CEPHMSGAUTH, where the returned value is

interpreted as the size of the front segment to send. If the result

value in the message is greater than the size of the memory buffer

allocated for the front segment, an out-of-bounds access occurs, and

the content of the memory region beyond this buffer is sent out.

This patch fixes the issue by treating only negative values in the

result field as errors. Positive values are therefore treated as success

in the same way as a zero value. Additionally, a BUG_ON is added to

_sendpreparedauthrequest() comparing the len parameter to

frontalloclen to prevent sending the message if it exceeds the bounds

of the allocation and to make it easier to catch any logic flaws leading

to this.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.1
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/1c439de70b1c3eb3c6bffa8245c16b9fc318f114, https://git.kernel.org/stable/c/2ae0afd98432536562fa8261538ae795446f0589, https://git.kernel.org/stable/c/38fdf04c602d52c42c67fc1617211492753b7e8b, https://git.kernel.org/stable/c/408e85ee708b6aa03eeb0220ffa0915f4d407181, https://git.kernel.org/stable/c/8517b6c8d2c759918ba0058cb6c7e14d59643202, https://git.kernel.org/stable/c/b7df9fbd4869fdfe09a3f501ffd228486521e062, https://git.kernel.org/stable/c/c2374b92c729d0388a538b3cde7b3e3b5e55ef39, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46119.json, https://nvd.nist.gov/vuln/detail/CVE-2026-46119, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.1

CVSS Score
0
10

Basic Information

Base CVSS
9.1
EPSS Probability
0.00525%
EPSS Percentile
0.42392%
Introduced Version
4e7a5dcd1bbab6560fbc8ada29a840e7a20ed7bc,2.6.34,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
1c439de70b1c3eb3c6bffa8245c16b9fc318f114,5.15.209,6.1.175,6.6.140,6.12.88,6.18.30,7.0.7,6.1.176-1,6.1.176-1~deb11u1,6.12.88-1,4.15.0-253.265,4.15.0-1194.207,5.4.0-1161.172~18.04.1,4.15.0-1204.219,5.4.0-1166.172~18.04.1,4.15.0-1187.204,5.4.0-1164.173~18.04.1,5.4.0-233.253~18.04.1,5.4.0-1107.112~18.04.1,4.15.0-1176.181,4.15.0-1156.167,5.4.0-1159.169~18.04.1,5.4.0-1144.157~18.04.1,5.4.0-233.253,5.4.0-1161.172,5.15.0-1111.118~20.04.1,5.4.0-1166.172,5.15.0-1116.125~20.04.1,5.4.0-1120.127,5.4.0-1164.173,5.15.0-1111.121~20.04.1,5.15.0-185.195~20.04.1,5.4.0-1107.112,5.15.0-1105.109~20.04.1,5.15.0-1106.112~20.04.1,5.4.0-1065.68,5.15.0-183.193~20.04.1,5.15.0-1063.63~20.04.1,5.4.0-1159.169,5.15.0-1108.114~20.04.1,5.4.0-1144.157,5.4.0-1079.83,6.8.0-134.134,6.8.0-1060.63,6.17.0-1019.19~24.04.1,6.8.0-1063.71,6.17.0-1021.21~24.04.1,6.8.0-1062.69,6.8.0-1063.69,6.17.0-1020.22~24.04.1,6.8.0-1058.64,6.8.0-1045.48,6.17.0-40.40~24.04.1,7.0.0-28.28~24.04.1,6.8.0-1060.61,6.8.0-134.134.1,6.8.0-1058.61,6.17.0-1026.26,6.8.0-1058.61.1,6.8.0-1029.30,6.17.0-1028.28,6.8.0-1057.58,6.17.0-1018.18~24.04.1,6.8.0-1060.64,6.8.0-1032.33,5.15.0-185.195,5.15.0-1111.118,6.8.0-1060.63~22.04.1,5.15.0-1116.125,6.8.0-1063.71~22.04.1,6.8.0-1062.69~22.04.1,5.15.0-1111.121,6.8.0-1063.69~22.04.1,5.15.0-1107.113,5.15.0-1094.102,6.8.0-136.136~22.04.1,5.15.0-1105.109,6.8.0-1060.61~22.04.1,5.15.0-1106.112,5.15.0-1103.108,5.15.0-183.193,6.8.0-134.134.1~22.04.1,5.15.0-1106.107,6.8.0-1058.61~22.04.1,5.15.0-1063.63,5.15.0-1052.52,5.15.0-1108.114,6.8.0-1057.58~22.04.1,5.15.0-1105.108,6.8.0-134.134~22.04.1,5.15.0-1074.78,0:5.15.209-147.245.amzn2,0:1.0-0.amzn2,1:6.12.88-119.157.amzn2023,1:1.0-0.amzn2023,1:6.18.30-61.116.amzn2023,1:6.1.175-219.357.amzn2023

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading