libceph: refresh auth->authorizer_buf{,_len} after authorizer update
Summary
| CVE | CVE-2026-68156 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-10 13:20:01 UTC |
| Updated | 2026-08-19 17:20:32 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authorizer_buf{,_len} after authorizer update ceph_x_create_authorizer() caches au->buf->vec.iov_base and au->buf->vec.iov_len in struct ceph_auth_handshake. These cached values are then used by the messenger connect code when sending the authorizer. ceph_x_update_authorizer() can rebuild the authorizer when a newer service ticket is available. If the rebuilt authorizer no longer fits in the existing buffer, ceph_x_build_authorizer() drops its reference to au->buf and allocates a new one. If this is the final reference, ceph_buffer_put() frees the old ceph_buffer and its vec.iov_base, but auth->authorizer_buf still points at that freed memory. A subsequent msgr1 reconnect can therefore queue the stale pointer and trigger a KASAN slab-use-after-free in _copy_from_iter() while tcp_sendmsg() copies the authorizer. Refresh auth->authorizer_buf and auth->authorizer_buf_len after a successful authorizer rebuild so the messenger sends the current buffer. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.006080000 probability, percentile 0.464590000 (date 2026-08-19)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 0bed9b5c523d577378b6f83eab5835fe30c27208 2334e9997308305ee4fd508fdfe6086c4150ed60 git | Not specified |
| CNA | Linux | Linux | affected 0bed9b5c523d577378b6f83eab5835fe30c27208 79a273df64238a4ade8b709689a78589f755b8ef git | Not specified |
| CNA | Linux | Linux | affected 0bed9b5c523d577378b6f83eab5835fe30c27208 26f814187abceee90dbb29a02133adb4786fbb13 git | Not specified |
| CNA | Linux | Linux | affected 0bed9b5c523d577378b6f83eab5835fe30c27208 9d37aec9ffe4e743dabc3f84502e9723e17a30d4 git | Not specified |
| CNA | Linux | Linux | affected 0bed9b5c523d577378b6f83eab5835fe30c27208 75e82e8944ac1efe9fdb88bd2f14d9a031282bdf git | Not specified |
| CNA | Linux | Linux | affected 0bed9b5c523d577378b6f83eab5835fe30c27208 0060ec912292a550198d8d18ac95b433c92a7091 git | Not specified |
| CNA | Linux | Linux | affected 0bed9b5c523d577378b6f83eab5835fe30c27208 5ecfcd5c05866f185357700b81b461dae4f5ebb2 git | Not specified |
| CNA | Linux | Linux | affected 0bed9b5c523d577378b6f83eab5835fe30c27208 937d61f86d377a3aa578adae7a3dfcecdddf9d89 git | Not specified |
| CNA | Linux | Linux | affected 29c65a277a64645af853e8c9a9b3dda0ddc421e0 git | Not specified |
| CNA | Linux | Linux | affected d2c7223497cf8228416c70e3f4238ddd6c5bdf3c git | Not specified |
| CNA | Linux | Linux | affected 3.4.50 3.5 semver | Not specified |
| CNA | Linux | Linux | affected 3.9.7 3.10 semver | Not specified |
| CNA | Linux | Linux | affected 3.10 | Not specified |
| CNA | Linux | Linux | unaffected 3.10 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.265 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.216 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.183 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.148 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.101 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.42 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.6 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/2334e9997308305ee4fd508fdfe6086c4150ed60 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/9d37aec9ffe4e743dabc3f84502e9723e17a30d4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/79a273df64238a4ade8b709689a78589f755b8ef | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/0060ec912292a550198d8d18ac95b433c92a7091 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/5ecfcd5c05866f185357700b81b461dae4f5ebb2 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/75e82e8944ac1efe9fdb88bd2f14d9a031282bdf | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/26f814187abceee90dbb29a02133adb4786fbb13 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/937d61f86d377a3aa578adae7a3dfcecdddf9d89 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.