← Πίσω στην αναζήτηση CVE

CVE-2026-68157

Περιγραφή

In the Linux kernel, the following vulnerability has been resolved: libceph: guard missing CRUSH type name lookup Localized read selection can walk a parent bucket whose name exists in the CRUSH map while its type has no matching entry in type_names. get_immediate_parent() then dereferences a NULL type_cn and passes an invalid pointer into strcmp(), causing a null-ptr-deref. Skip such malformed parent buckets unless both the bucket name and type name metadata are present. This keeps malformed hierarchy data from crashing locality lookup and safely falls back to -not local-. [ idryomov: add WARN_ON_ONCE ]

EPSS 0.2%Κίνδυνος 0
Προβολή πηγής
Δημοσίευση
2026-08-10 13:20:01
Τελευταία τροποποίηση
2026-08-10 13:20:01
Διάνυσμα
Pending