CVE-2026-43405 Details
Description
In the Linux kernel, the following vulnerability has been resolved: libceph: Use u32 for non-negative values in ceph_monmap_decode() This patch fixes unnecessary implicit conversions that change signedness of blob_len and num_mon in ceph_monmap_decode(). Currently blob_len and num_mon are (signed) int variables. They are used to hold values that are always non-negative and get assigned in ceph_decode_32_safe(), which is meant to assign u32 values. Both variables are subsequently used as unsigned values, and the value of num_mon is further assigned to monmap->num_mon, which is of type u32. Therefore, both variables should be of type u32. This is especially relevant for num_mon. If the value read from the incoming message is very large, it is interpreted as a negative value, and the check for num_mon > CEPH_MAX_MON does not catch it. This leads to the attempt to allocate a very large chunk of memory for monmap, which will most likely fail. In this case, an unnecessary attempt to allocate memory is performed, and -ENOMEM is returned instead of -EINVAL.
A vulnerability exists in the Linux kernel's libceph component, specifically within the ceph_monmap_decode() function. The issue arises from the use of signed integer variables to represent non-negative values, leading to potential memory allocation problems. The variables blob_len and num_mon, currently defined as signed integers, are assigned values through a function intended for unsigned 32-bit integers. This misalignment allows for the possibility of interpreting large values as negative, bypassing crucial validation checks and causing excessive memory allocation attempts that are likely to fail. The vulnerability affects the Linux kernel stable tree.
Users can upgrade to the latest version of the Linux kernel stable tree, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/08bc6173fd611ad5a40f472bf5f15b92aea0fe40 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5f2806684b05bd24d05c091083b8e2517ba8ffac | kernel.org | Patch |
| https://git.kernel.org/stable/c/770444611f047dbfd4517ec0bc1b179d40c2f346 | kernel.org | Patch |
| https://git.kernel.org/stable/c/86f7060cd638d6eb042e8ed780fb83a59ca0dcb3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b268984ae88cb0dcd7a8e8263962c748448e26e8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ba0a4df8c563536857dcbf7b4dbd0f2a15f57ace | kernel.org | Patch |
| https://git.kernel.org/stable/c/ee5588e2bc41acb73f6676c0520420c107cd0140 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-908 | Use of Uninitialized Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.11, < 5.15.203 >= 5.16, < 6.1.167 >= 6.2, < 6.6.130 >= 6.7, < 6.12.78 >= 6.13, < 6.18.19 >= 6.19, < 6.19.9 7.0 rc1 7.0 rc2 7.0 rc3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 21, 2026 | Initial Analysis | [email protected] |
| May 11, 2026 | CVE Modified | kernel.org |
| May 8, 2026 | New CVE Received | kernel.org |