In the Linux kernel, the following vulnerability has been resolved:
libceph: reject zero bucket types in crush_decode
CRUSH bucket type 0 is reserved for devices. The mapper relies on that invariant and uses type 0 to identify leaf devices.
If crush_decode() accepts a bucket with type 0, a malformed CRUSH map can make the mapper treat a negative bucket ID as a device and pass it to is_out(), which then indexes the OSD weight array with a negative value.
Reject zero bucket types while decoding the CRUSH map so the invalid state never reaches the mapper.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel6.12-tools-debuginfoUpgrade kernel6.12-modules-extra-commonUpgrade perf6.12-debuginfoUpgrade kernel6.12-develUpgrade kernel6.12-tools-develUpgrade bpftool6.12-debuginfoUpgrade python3-perf6.12Upgrade kernel6.12-debuginfo-common-x86_64Upgrade kernel6.12-toolsUpgrade kernel6.12-modules-extraUpgrade python3-perf6.12-debuginfoUpgrade bpftool6.12Upgrade kernel6.12-debuginfoUpgrade kernel6.12Upgrade perf6.12Upgrade kernel6.12-debuginfo-common-aarch64Upgrade kernel6.12-headersUpgrade kernel-livepatch-6.12.103-127.188 | Sep 1, 2026 | Aug 10, 2026 |
| Debian | — | Upgrade linuxUpgrade linux-6.12 | Aug 11, 2026 | Aug 11, 2026 |
| Redhat_linux | — | No solution exists | Aug 13, 2026 | Aug 10, 2026 |
| Ubuntu | — | No solution existsUpgrade linux-image-nvidia-tegra-rt-6.8Upgrade linux-image-nvidia-tegra-rtUpgrade linux-image-6.8.0-1035-nvidia-tegraUpgrade linux-image-nvidia-tegra-6.8Upgrade linux-image-6.8.0-1035-nvidia-tegra-rtUpgrade linux-image-nvidia-tegra | Sep 21, 2026 | Sep 18, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 17, 2026 | Aug 10, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub