CVE-2026-68160
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix pre-auth out-of-bounds read on snaptrace in cephhandlecaps()
cephhandlecaps() reads snaptracelen from the wire-format
cephmdscaps header and uses it unconditionally to build a fake
end pointer (snaptrace + snaptrace_len) that is later handed to
cephupdatesnaptrace() in the CEPHCAPOPIMPORT case:
snaptrace = h + 1;
snaptracelen = le32tocpu(h->snaptrace_len);
p = snaptrace + snaptrace_len;
...
case CEPHCAPOP_IMPORT:
if (snaptrace_len) {
...
if (cephupdatesnap_trace(mdsc, snaptrace,
snaptrace + snaptrace_len,
false, &realm)) { ... }
cephupdatesnaptrace() then decodes a struct cephmdssnaprealm
from snaptrace using cephdecodeneed(&p, e, sizeof(*ri), bad)
with the attacker-supplied fake end e == snaptrace + snaptrace_len.
With snaptrace_len == 0xFFFFFFFF the bound check is trivially
satisfied, ri = p reads sizeof(struct cephmdssnap_realm) past
the legitimate msg->front buffer, and ri->num_snaps /
ri->numpriorparent_snaps then drive further out-of-bounds
reads of the encoded snap arrays.
The eleven msgversion >= 2 .. msgversion >= 12 decoder blocks
above the op switch each catch this OOB through their
cephdecode*safe() / cephdecode_need() helpers, but they sit
behind a hdr.version-gated if, so a malicious or compromised
MDS that sets msg->hdr.version = 1 reaches the IMPORT path with
no version-gated decoder having validated snaptracelen. The
shape has been present since cephhandlecaps() was introduced.
Validate snaptracelen against the message front buffer before
consuming it, using the canonical cephdecodeneed() / cephhasroom()
helper. The helper bounds the length with subtraction (n <= end - p,
guarded by end >= p) rather than pointer addition, so it is wrap-safe
for the attacker-controlled u32 length on 32-bit builds where
p + snaptracelen could overflow the address space. This matches the
rest of the ceph decode path (e.g. the poolnslen check a few lines
below), and the existing goto bad cleanup already covers this exit
path.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/03b417afce19ee6b6e61f1bbbbebac924c9f36d1, https://git.kernel.org/stable/c/0c011137194036424e974677e0f1592e22a33d8c, https://git.kernel.org/stable/c/4dbc71bcaf9a30abf3920a4e2cc4ed33bba78c02, https://git.kernel.org/stable/c/71893c342a26bcff92eaab0b2b75d64aed19308a, https://git.kernel.org/stable/c/9081c71796724ffe96cba253f68fbe42363c5295, https://git.kernel.org/stable/c/a4228b93706fb74a484e6ffb271c1cc2af3a2ddb, https://git.kernel.org/stable/c/cc93f68a31c9b831abf2db8647b5f5b10329d793, https://git.kernel.org/stable/c/f913192fc782288e060dafc329b2346934be34cc, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68160.json, https://nvd.nist.gov/vuln/detail/CVE-2026-68160, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git