CyberRota
← Ana sayfaya dön

CVE-2026-52954

HIGH · CVSS 7.5 EPSS %0.53

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-24T17:17:05.530 · Çekilme zamanı: 2026-06-30T18:31:39.900532+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-52954
Severity
HIGH
CVSS
7.5
EPSS
%0.53
Linux

Orijinal NVD Açıklaması

In the Linux kernel, the following vulnerability has been resolved: libceph: handle rbtree insertion error in decode_choose_args() A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself contains a CRUSH map. The received CRUSH map may optionally contain choose_args that get decoded in decode_choose_args(). In this function, num_choose_arg_maps is read from the message, and a corresponding number of crush_choose_arg_maps gets decoded afterwards. Each crush_choose_arg_map has a choose_args_index, which serves as the key when inserting it into the choose_args rbtree of the decoded crush_map. If a (potentially corrupted) message contains two crush_choose_arg_maps with the same index, the assertion in insert_choose_arg_map() triggers a kernel BUG when trying to insert the second crush_choose_arg_map. This patch fixes the issue by switching to the non-asserting rbtree insertion function and rejecting the message if the insertion fails. [ idryomov: changelog ]