CVE-2026-80558 PUBLISHED

libceph: Avoid using invalid osd indices from primary_temp

Assigner: Linux
Reserved: 26.08.2026 Published: 26.08.2026 Updated: 26.08.2026

In the Linux kernel, the following vulnerability has been resolved:

libceph: Avoid using invalid osd indices from primary_temp

A corrupted osdmap received from a Ceph monitor or OSD may contain osd indices in its pg_temp, primary_temp, pg_upmap, and pg_upmap_items parts that don't exist, i.e., that are greater than max_osd or smaller than CEPH_HOMELESS_OSD (-1). These indices are used to create the up and acting set in ceph_pg_to_up_acting_osds(), called from calc_target(). While most of these osd indices are checked, the one from primary_temp is not. Subsequently, this may lead to calc_target() returning this (potentially invalid) index as target osd for a (linger) request. Because the osd_state, osd_weight, and osd_addr arrays only contain max_osd entries (with indices 0 to max_osd -1), this leads to out-of-bounds accesses when trying to read values from these arrays.

This patch fixes the issue by adding a check to get_temp_osds(), so that only valid osd indices from primary_temp are used, and it falls back to using the primary from pg_temp or the up set if it is invalid.

[ idryomov: changelog ]

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 5e8d4d36bf23bb7baf027c479d54395840219928 to 505fc50b8ff8e687b7e3ef6866269dea27366224 (excl.)
  • affected from 5e8d4d36bf23bb7baf027c479d54395840219928 to 1c705fe8e59c6b16f48964973fb23c8ec4735b73 (excl.)
  • affected from 5e8d4d36bf23bb7baf027c479d54395840219928 to dfe1877d351b99eb1b1a62a3fc2d174220e88e20 (excl.)
  • affected from 5e8d4d36bf23bb7baf027c479d54395840219928 to e2ffeec85201b2bb748e99e12539ee1b92f62796 (excl.)
  • affected from 5e8d4d36bf23bb7baf027c479d54395840219928 to 6799d4a916ffcb3d450d8440f9fe0f0862f768d6 (excl.)
  • affected from 5e8d4d36bf23bb7baf027c479d54395840219928 to 4f392fec075562dc93bb0c69f37423ca2af9b48f (excl.)
  • affected from 5e8d4d36bf23bb7baf027c479d54395840219928 to e009c5f0ad634c62f5c48a41f1f3c019ecf52555 (excl.)
  • affected from 5e8d4d36bf23bb7baf027c479d54395840219928 to 3660b98d1204b419f6a77e9a295f148dcf38d042 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.15 is affected
  • unaffected from 0 to 3.15 (excl.)
  • unaffected from 5.10.266 to 5.10.* (incl.)
  • unaffected from 5.15.217 to 5.15.* (incl.)
  • unaffected from 6.1.184 to 6.1.* (incl.)
  • unaffected from 6.6.153 to 6.6.* (incl.)
  • unaffected from 6.12.105 to 6.12.* (incl.)
  • unaffected from 6.18.46 to 6.18.* (incl.)
  • unaffected from 7.1.10 to 7.1.* (incl.)
  • unaffected from 7.2 to * (incl.)

References