Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-68160

ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
Back to all
CVE

CVE-2026-68160

ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()

In the Linux kernel, the following vulnerability has been resolved:

ceph: fix pre-auth out-of-bounds read on snaptrace in cephhandlecaps()

cephhandlecaps() reads snaptracelen from the wire-format

cephmdscaps header and uses it unconditionally to build a fake

end pointer (snaptrace + snaptrace_len) that is later handed to

cephupdatesnaptrace() in the CEPHCAPOPIMPORT case:

    snaptrace     = h + 1;

    snaptracelen = le32tocpu(h->snaptrace_len);

    p             = snaptrace + snaptrace_len;

    ...

    case CEPHCAPOP_IMPORT:

        if (snaptrace_len) {

            ...

            if (cephupdatesnap_trace(mdsc, snaptrace,

                                       snaptrace + snaptrace_len,

                                       false, &realm)) { ... }

cephupdatesnaptrace() then decodes a struct cephmdssnaprealm

from snaptrace using cephdecodeneed(&p, e, sizeof(*ri), bad)

with the attacker-supplied fake end e == snaptrace + snaptrace_len.

With snaptrace_len == 0xFFFFFFFF the bound check is trivially

satisfied, ri = p reads sizeof(struct cephmdssnap_realm) past

the legitimate msg->front buffer, and ri->num_snaps /

ri->numpriorparent_snaps then drive further out-of-bounds

reads of the encoded snap arrays.

The eleven msgversion >= 2 .. msgversion >= 12 decoder blocks

above the op switch each catch this OOB through their

cephdecode*safe() / cephdecode_need() helpers, but they sit

behind a hdr.version-gated if, so a malicious or compromised

MDS that sets msg->hdr.version = 1 reaches the IMPORT path with

no version-gated decoder having validated snaptracelen. The

shape has been present since cephhandlecaps() was introduced.

Validate snaptracelen against the message front buffer before

consuming it, using the canonical cephdecodeneed() / cephhasroom()

helper.  The helper bounds the length with subtraction (n <= end - p,

guarded by end >= p) rather than pointer addition, so it is wrap-safe

for the attacker-controlled u32 length on 32-bit builds where

p + snaptracelen could overflow the address space.  This matches the

rest of the ceph decode path (e.g. the poolnslen check a few lines

below), and the existing goto bad cleanup already covers this exit

path.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/03b417afce19ee6b6e61f1bbbbebac924c9f36d1, https://git.kernel.org/stable/c/0c011137194036424e974677e0f1592e22a33d8c, https://git.kernel.org/stable/c/4dbc71bcaf9a30abf3920a4e2cc4ed33bba78c02, https://git.kernel.org/stable/c/71893c342a26bcff92eaab0b2b75d64aed19308a, https://git.kernel.org/stable/c/9081c71796724ffe96cba253f68fbe42363c5295, https://git.kernel.org/stable/c/a4228b93706fb74a484e6ffb271c1cc2af3a2ddb, https://git.kernel.org/stable/c/cc93f68a31c9b831abf2db8647b5f5b10329d793, https://git.kernel.org/stable/c/f913192fc782288e060dafc329b2346934be34cc, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68160.json, https://nvd.nist.gov/vuln/detail/CVE-2026-68160, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00761%
EPSS Percentile
0.52658%
Introduced Version
a8599bd821d084d04a3290fffae1071624ec00ea,2.6.34,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
4dbc71bcaf9a30abf3920a4e2cc4ed33bba78c02,5.10.265,5.15.216,6.1.183,6.6.148,6.12.101,6.18.42,7.1.6,6.12.101-1~deb12u1,6.12.101-1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading