Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-80557

libceph: fix OOB read in decode_watchers() via missing bounds check
Back to all
CVE

CVE-2026-80557

libceph: fix OOB read in decode_watchers() via missing bounds check

In the Linux kernel, the following vulnerability has been resolved:

libceph: fix OOB read in decode_watchers() via missing bounds check

cephstartdecoding() validates that struct_len bytes remain in the

buffer after the encoding header, but accepts struct_len=0 as valid:

cephdecodeneed(p, end, 0, bad) always passes. When a malicious or

compromised OSD sends an objlistwatchresponset reply with

structlen=0, cephstart_decoding() returns success with p == end,

leaving zero bytes guaranteed for subsequent reads.

The immediately following cephdecode32(p) in decode_watchers() has

no preceding bounds check. With p == end this is a 4-byte read past

the validated buffer boundary. The garbage value is then passed

directly to kzalloc_objs() as the watcher count.

The sibling function decode_watcher() already uses the safe variants

(cephdecodecopysafe, cephdecode64safe, cephdecodeskip_32)

after its own cephstartdecoding() call. decode_watchers() is the

only site that uses the bare variant, confirming an oversight.

Fix by replacing cephdecode32(p) with cephdecode32_safe(p, end,

*num_watchers, bad), consistent with the established pattern.

Attacker model: a malicious or compromised OSD in a multi-tenant Ceph

deployment (e.g. cloud) can trigger this against any kernel client

that calls CEPHOSDOPLISTWATCHERS, without any further privileges

beyond OSD session establishment.

[ idryomov: trim changelog ]

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/00ead17c7de137a692edee59f2772e6af687e8eb, https://git.kernel.org/stable/c/1c824e7c75bb4adf19553dd4ea944a5d83096be8, https://git.kernel.org/stable/c/7130d94846dadbb97b6b7f4d78a3a7bba6e3daa1, https://git.kernel.org/stable/c/85479b7d65b4ebcb07fbbe57230976793974ab4a, https://git.kernel.org/stable/c/c59219a6b62d74936963983e5815524c3de8dd79, https://git.kernel.org/stable/c/cb8246e5846dbbe34930903a90c7a90dd8e5910b, https://git.kernel.org/stable/c/eab3eeb68bfc639d74f27256f05546af5c4f787d, https://git.kernel.org/stable/c/f161be39201eb5f9b1f58fb8f90b8a9cd3931eb6, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80557.json, https://nvd.nist.gov/vuln/detail/CVE-2026-80557, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00525%
EPSS Percentile
0.42707%
Introduced Version
a4ed38d7a180f184a6e7aedd09db9ca4b1e6a71c,4.9.0,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
00ead17c7de137a692edee59f2772e6af687e8eb,5.10.267,5.15.218,6.1.185,6.6.154,6.12.106,6.18.47,7.1.10,6.1.187-1,6.12.107-1~deb12u1,6.12.107-1,6.8.0-1036.39,0:6.12.0-207.111.5.1.el10uek,0:5.15.0-325.220.5.el8uek,0:6.12.0-207.111.5.1.el9uek,0:5.15.0-325.220.5.el9uek,1:6.1.186-228.374.amzn2023,1:1.0-0.amzn2023,1:6.18.48-107.148.amzn2023,0:5.10.268-266.1092.amzn2,0:1.0-0.amzn2,0:5.15.220-153.252.amzn2

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading