Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-68160

In the Linux kernel, the following vulnerability has been resolved: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() ceph_handle_caps() reads snap_trace_len from the wire-for...
Back to all
CVE

DEBIAN-CVE-2026-68160

In the Linux kernel, the following vulnerability has been resolved: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() ceph_handle_caps() reads snap_trace_len from the wire-for...

In the Linux kernel, the following vulnerability has been resolved:  ceph: fix pre-auth out-of-bounds read on snaptrace in cephhandlecaps()  cephhandlecaps() reads snaptracelen from the wire-format cephmdscaps header and uses it unconditionally to build a fake end pointer (snaptrace + snaptracelen) that is later handed to cephupdatesnaptrace() in the CEPHCAPOPIMPORT case:      snaptrace     = h + 1;     snaptracelen = le32tocpu(h->snaptracelen);     p             = snaptrace + snaptracelen;     ...     case CEPHCAPOPIMPORT:         if (snaptracelen) {             ...             if (cephupdatesnaptrace(mdsc, snaptrace,                                        snaptrace + snaptracelen,                                        false, &realm)) { ... }  cephupdatesnaptrace() then decodes a struct cephmdssnaprealm from snaptrace using cephdecodeneed(&p, e, sizeof(*ri), bad) with the attacker-supplied fake end e == snaptrace + snaptracelen. With snaptracelen == 0xFFFFFFFF the bound check is trivially satisfied, ri = p reads sizeof(struct cephmdssnaprealm) past the legitimate msg->front buffer, and ri->numsnaps / ri->numpriorparentsnaps then drive further out-of-bounds reads of the encoded snap arrays.  The eleven msgversion >= 2 .. msgversion >= 12 decoder blocks above the op switch each catch this OOB through their cephdecode*safe() / cephdecodeneed() helpers, but they sit behind a hdr.version-gated if, so a malicious or compromised MDS that sets msg->hdr.version = 1 reaches the IMPORT path with no version-gated decoder having validated snaptracelen. The shape has been present since cephhandlecaps() was introduced.  Validate snaptracelen against the message front buffer before consuming it, using the canonical cephdecodeneed() / cephhasroom() helper.  The helper bounds the length with subtraction (n <= end - p, guarded by end >= p) rather than pointer addition, so it is wrap-safe for the attacker-controlled u32 length on 32-bit builds where p + snaptracelen could overflow the address space.  This matches the rest of the ceph decode path (e.g. the poolns_len check a few lines below), and the existing goto bad cleanup already covers this exit path.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-68160

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
6.1.187-1,6.12.101-1,7.1.6-1,6.12.101-1~deb12u1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading