CyberRota
← Ana sayfaya dön

CVE-2026-52958

CRITICAL · CVSS 9.1 EPSS %0.54

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-24T17:17:06.033 · Çekilme zamanı: 2026-06-30T18:31:41.198301+00:00

CyberRota Yorumu

Bellek tüketimine neden olabilir.

CVE
CVE-2026-52958
Severity
CRITICAL
CVSS
9.1
EPSS
%0.54
Linux

Orijinal NVD Açıklaması

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdmap_decode() When decoding osd_state and osd_weight from an incoming osdmap in osdmap_decode(), both are decoded for each osd, i.e., map->max_osd times. The ceph_decode_need() check only accounts for sizeof(*map->osd_weight) once. This can potentially result in an out-of-bounds memory access if the incoming message is corrupted such that the max_osd value exceeds the actual content of the osdmap message. This patch fixes the issue by changing the corresponding part in the ceph_decode_need() check to account for map->max_osd*sizeof(*map->osd_weight).