CVE-2026-52954 Details
Description
In the Linux kernel, the following vulnerability has been resolved: libceph: handle rbtree insertion error in decode_choose_args() A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself contains a CRUSH map. The received CRUSH map may optionally contain choose_args that get decoded in decode_choose_args(). In this function, num_choose_arg_maps is read from the message, and a corresponding number of crush_choose_arg_maps gets decoded afterwards. Each crush_choose_arg_map has a choose_args_index, which serves as the key when inserting it into the choose_args rbtree of the decoded crush_map. If a (potentially corrupted) message contains two crush_choose_arg_maps with the same index, the assertion in insert_choose_arg_map() triggers a kernel BUG when trying to insert the second crush_choose_arg_map. This patch fixes the issue by switching to the non-asserting rbtree insertion function and rejecting the message if the insertion fails. [ idryomov: changelog ]
A vulnerability in the Linux kernel's libceph component has been addressed. The issue arose in the 'decode_choose_args()' function, which processes 'CEPH_MSG_OSD_MAP' messages containing OSD and CRUSH maps. If a corrupted message included two 'crush_choose_arg_maps' with the same index, it triggered a kernel BUG by violating an assertion during the second insertion into the 'choose_args' red-black tree. The vulnerability has been fixed by changing to a non-asserting insertion method and rejecting messages where the insertion fails.
Users can upgrade to the patched version of the Linux kernel available in the official Linux repositories or through the Linux Kernel Archive.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0a1265a9ab875f92b6a3ffb497404f46cf9d76a3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/0b6a3bcb91bc5bfeda39f0df3b71bab62c13e9da | kernel.org | Patch |
| https://git.kernel.org/stable/c/4d2b37abda9536808655830d683dc491d31741a8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/534ebc08df97c47d4c7596f336fa31ecbf91519c | kernel.org | Patch |
| https://git.kernel.org/stable/c/80c73bd1b2b04355d1d0c29be8ccbd25a380905d | kernel.org | Patch |
| https://git.kernel.org/stable/c/c7bf7864e2924fa5508ac270b0e9364bc13d5a6c | kernel.org | Patch |
| https://git.kernel.org/stable/c/d289478cfc0bcf81c7914200d6abdcb78bd04ded | kernel.org | Patch |
| https://git.kernel.org/stable/c/f47430fc1f815e87406e2d3b4e476eff1bc7fd9b | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-617 | Reachable Assertion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.13, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.141 >= 6.7, < 6.12.91 >= 6.13, < 6.18.33 >= 6.19, < 7.0.10 7.1 rc1 7.1 rc2 7.1 rc3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | Initial Analysis | [email protected] |
| Jun 29, 2026 | CVE Modified | kernel.org |
| Jun 28, 2026 | CVE Modified | kernel.org |
| Jun 24, 2026 | New CVE Received | kernel.org |